CVE-2026-33347 describes an allowlist bypass vulnerability in league/commonmark, a PHP Markdown parser, affecting versions 2.3.0 through 2.8.1. The flaw resides in the Embed extension's DomainFilteringAdapter, where a missing hostname boundary assertion allows an attacker to bypass domain restrictions by appending malicious suffixes to allowed domains (e.g., "youtube.com.evil" for "youtube.com"). Rated as Medium severity (CVSS 6.3), it carries a network attack vector and low attack complexity, potentially enabling content injection or other security control bypasses. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, reflected by a very low EPSS score. The vulnerability has been addressed in version 2.8.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 2.8.2CPE matchmatch criteria | cpe:2.3:a:thephpleague:commonmark:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.