CVE-2026-27627Disclosure(localhostlabs / karakeep)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess uses it directly without running it through DOMPurify. Every other content source in the crawler goes through Readability + DOMPurify, but the Reddit path skips both. Since this content ends up in `dangerouslySetInnerHTML` in the reader view, any malicious HTML in the Reddit response gets executed in the user's browser. Version 0.31.0 contains a patch for this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • karakeep

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
karakeep

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-02: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 102-2503-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure3
2026-03-021
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27627 Cross-Site Scripting in Karakeep 0.30.0 Reddit Metascraper Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27627

    Post summary

    A cross‑site scripting vulnerability (CVE‑2026‑27627) was disclosed in the Karakeep 0.30.0 Reddit Metascraper plugin, with no evidence of exploitation or patch information provided.

    0001044
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27627 (CVSS:8.2, HIGH) is Analyzed. Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `reada..https://nvd.nist.gov/vuln/detail/CVE-2026-27627 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27627 with a CVSS score of 8.2, noting a potential issue in Karakeep 0.30.0's Reddit metascraper plugin, but provides no evidence of exploitation, patches, or PoC.

    0000039
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27627 Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess u… https://www.cve.org/CVERecord?id=CVE-2026-27627

    Post summary

    The CVE record describes a bug in Karakeep’s HTML parsing when using the Reddit metascraper plugin, but no PoC, exploit, or patch details are provided.

    00000111
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-27627 pertains to a cross-site scripting (XSS) vulnerability in the Karakeep application, specifically in version 0.30.0. The issue arises from the handling of content fetched from Reddit via the metascraper plugin. When Reddit returns `readableContentHtml`, this HTML content is directly injected into the application's DOM via React's `dangerouslySetInnerHTML` without sanitization through DOMPurify. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #XSS https://cvetodo.com/cve/CVE-2026-27627

    Post summary

    The post announces CVE-2026-27627, a cross‑site scripting vulnerability in Karakeep 0.30.0 caused by unsanitized Reddit content injected via React's `dangerouslySetInnerHTML`. No PoC, exploit, or patch is mentioned.

    0000038
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applocalhostlabskarakeep0.30.0--

Explore more