Vulnerabilities/

@diplodoc/search-extension allows stored XSS via Markdown file title

Severity:
Medium

Description

@diplodoc/search-extension 1.0.0 through 3.0.2 allows stored XSS via .md file title.

Recommendation

Update the @diplodoc/search-extension package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@diplodoc/search-extension
Anything's wrong? Let us know Last updated on May 07, 2026