Vulnerabilities/

Cross-site Scripting in markdown-it-highlightjs

Severity:
Medium

Description

This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature.

Recommendation

Update the markdown-it-highlightjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
markdown-it-highlightjs
Anything's wrong? Let us know Last updated on September 05, 2023