Generated remediation guidance and an executive summary. No account required.
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2.
Cite this page
CVE-2026-33347. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-33347
Use CWE-79, Thephpleague vendor hub and Commonmark product page to widen CVE-2026-33347 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-10010, CVE-2018-20583 and CVE-2026-30838 for nearby disclosures in the same product family.