Vulnerabilities/

Cross-Site Scripting in markdown-it-katex

Severity:
High

Description

All versions of markdown-it-katex are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape error messages, which may allow attackers to execute arbitrary JavaScript in a victim’s browser by triggering an error.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
markdown-it-katex
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing