CVE-2026-41591Disclosure(openjsf / marko)

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openjsf marko systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is interpolated into a <script> or <style> tag the Marko runtime failed to prevent tag breakout when the closing tag used non-lowercase casing. An attacker able to place input inside a <script> or <style> block could break out of the tag with </SCRIPT>, </Style>, etc. and inject arbitrary HTML/JavaScript, resulting in cross-site scripting. This issue has been patched in marko version 5.38.36 and @marko/runtime-tags 6.0.164.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • marko
  • marko\/runtime-tags

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-08); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
markomarko\/runtime-tags

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-26: 1Mentions · 2026-05-08: 2Mentions · 2026-05-30: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-30: 104-2605-0805-30
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-261
Disclosure1
2026-05-082
Disclosure1Patch1
2026-05-301
Disclosure1
Full discourse4 posts
  • K0w4lzk1_@k0w4lzk1
    Disclosure

    Found and Disclosed my first CVE (CVE-2026-41591) Rather Small but happy to get the ball rolling Huge Thanks to my mentors at @teambi0s as well as @dylan_piercey for the smooth disclosure process https://github.com/advisories/GHSA-x9fj-57fh-c8wq

    Post summary

    The user announced the discovery and disclosure of a new CVE (CVE‑2026‑41591) and thanked mentors for the disclosure process.

    350253598
    69 followersView on X
  • teambi0s@teambi0s
    Disclosure

    Proud to share that our Web Team Lead, @k0w4lzk1, has been credited with two CVEs: • CVE-2026-35228: SQL Injection in Oracle's MCP Server Helper Tool • CVE-2026-41591: XSS in eBay's Marko framework Congrats to Kartik on the disclosures!

    Post summary

    The post celebrates the discovery of two new CVEs—a SQL injection in Oracle's MCP Server Helper Tool and an XSS in eBay's Marko framework—without providing PoC, exploitation details, or patch information.

    3202711.1K
    3.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41591 Cross-Site Scripting via Tag Breakout in Marko Below 5.38.36 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41591

    Post summary

    The text is a brief disclosure of CVE-2026-41591, describing an XSS flaw via tag breakout in Marko versions below 5.38.36, with a link to additional details but no PoC, exploit, or patch information.

    0000045
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-41591 Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/runtime-tags 6.0.164, when dynamic text is inter… https://www.cve.org/CVERecord?id=CVE-2026-41591

    Post summary

    The post highlights that CVE-2026-41591 is corrected by upgrading to Marko 5.38.36 or @marko/runtime-tags 6.0.164, but provides no detailed technical description or evidence of exploitation.

    0000062
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsfmarko-node.js-
Appopenjsfmarko\/runtime-tags-node.js-

Explore more