Logseq Sandbox Escape Vulnerability Allowing Arbitrary JavaScript Execution

Vulnerability

A sandbox escape vulnerability has been identified in Logseq, specifically in version 0.10.15 and prior. This flaw allows plugins running in sandboxed iframes to inject arbitrary HTML attributes, including event handlers, into their container elements within the host DOM. The absence of a Content Security Policy (CSP) enables malicious plugins to execute arbitrary JavaScript in the privileged host context, potentially accessing filesystem APIs without authorization.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of JavaScript in the host context, with possible access to sensitive filesystem APIs.

Added: Jun 9, 2026, 2:50 PM
Updated: Jun 9, 2026, 2:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.6
remediation
0.0
relevance
9.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.