Vulnerabilities/

Cross-Site Scripting in mrk.js

Severity:
High

Description

Versions of mrk.js before 2.0.1 are vulnerable to cross-site scripting (XSS) when markdown is converted to HTML.

Recommendation

Update the mrk.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mrk.js
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing