Description
All versions of markdown-it-toc-and-anchor are vulnerable to Denial of Service. Parsing markdown containing **text**+\n@[toc] causes the application to enter and infinite loop.
Recommendation
Update the markdown-it-toc-and-anchor package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.2.0
- Patched version(s): 4.2.0
References
Could your website be exposed too?
SmartScanner can check your website for Denial of Service in markdown-it-toc-and-anchor and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service in markdown - Vulnerability
- Denial of Service in mem - Vulnerability
- Denial of Service in rgb2hex - Vulnerability
- Regular Expression Denial of Service in Acorn - Vulnerability


