| Summary | Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" without proper sanitization, allowing the execution of arbitrary code in the privileged host context. |
|---|---|
| Publication Date | June 9, 2026, 11:16 p.m. |
| Registration Date | June 10, 2026, 4:16 a.m. |
| Last Update | June 9, 2026, 11:47 p.m. |