Description
Versions 1.4.0 and earlier of remarkable are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of remarkable did not properly whitelist link protocols, and consequently allowed javascript: to be used.
Recommendation
Update the remarkable package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.1
- Patched version(s): 1.4.1
References
Related Issues
- Multiple Content Injection Vulnerabilities in marked - CVE-2014-3743
- Content Injection via TileJSON attribute in mapbox.js - CVE-2017-1000042
- Content Injection via TileJSON Name in mapbox.js - CVE-2017-1000043
- Denial of Service and Content Injection in i18n-node-angular - CVE-2016-10524
You might also like:
- Tags:
- npm
- remarkable
Anything's wrong? Let us know Last updated on April 03, 2023


