Description
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.
Recommendation
Update the markdown-to-jsx
package to the latest compatible version. Followings are version details:
- Affected version(s): < 7.4.0
- Patched version(s): 7.4.0
References
Related Issues
- tarteaucitron Cross-site Scripting (XSS) - CVE-2025-1467
- uPlot Prototype Pollution vulnerability - CVE-2024-21489
- FUXA local file inclusion vulnerability - CVE-2023-31718
- FUXA vulnerable to Local File Inclusion - CVE-2023-31716
- Tags:
- npm
- markdown-to-jsx
Anything's wrong? Let us know Last updated on October 15, 2024