Vulnerabilities/

Content Injection in remarkable

Severity:
High

Description

Versions 1.4.0 and earlier of remarkable are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of remarkable did not properly whitelist link protocols, and consequently allowed javascript: to be used.

Recommendation

Update the remarkable package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
remarkable
Anything's wrong? Let us know Last updated on April 03, 2023