[Medium] CVE-2026-47901 – Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed...
Medium CVE-2026-47901 Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Due to a disabled Content Security Policy (CSP), this allows a malicious plugin...