Vulnerabilities/

Denial of Service in markdown-it-toc-and-anchor

Severity:
High

Description

All versions of markdown-it-toc-and-anchor are vulnerable to Denial of Service. Parsing markdown containing **text**+\n@[toc] causes the application to enter and infinite loop.

Recommendation

Update the markdown-it-toc-and-anchor package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
markdown-it-toc-and-anchor
Anything's wrong? Let us know Last updated on December 07, 2023