CVE-2026-27627
Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns readableContentHtml, the HTML parsing subprocess uses it directly without running it through DOMPurify. Every other content source in the crawler goes through Readability + DOMPurify, but the Reddit path skips both. Since this content ends up in dangerouslySetInnerHTML in the reader view, any malicious HTML in the Reddit response gets executed in the user's browser. Version 0.31.0 contains a patch for this issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/karakeep-app/karakeep/releases/tag/v0.31.0, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27627.json, https://github.com/karakeep-app/karakeep/security/advisories/GHSA-mg93-f9mw-wpgj, https://nvd.nist.gov/vuln/detail/CVE-2026-27627, https://github.com/karakeep-app/karakeep/commit/ba3db953c0d8675e2e3ecc29113a332b570b2cb9
