Vulnerability library
Security checkApril 03, 2023

Content Injection in remarkable

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmremarkable

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Versions 1.4.0 and earlier of remarkable are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of remarkable did not properly whitelist link protocols, and consequently allowed javascript: to be used.

Recommendation

Update the remarkable package to the latest compatible version. Followings are version details:

  • Affected version(s): < 1.4.1
  • Patched version(s): 1.4.1

References

Could your website be exposed too?

SmartScanner can check your website for Content Injection in remarkable and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated April 03, 2023