Description
A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown library.
Recommendation
Update the @github/paste-markdown package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.4
- Patched version(s): 0.3.4
References
Related Issues
- Clipboard-based XSS - CVE-2021-41086
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - CVE-2025-53892
- DOM-based XSS in gmail-js - CVE-2016-1000228
- vue-i18n's escapeParameterHtml does not prevent DOM-based XSS through its tag attributes - vue-i18n - CVE-2025-53892
You might also like:
- Tags:
- npm
- @github/paste-markdown
Anything's wrong? Let us know Last updated on February 01, 2023


