discord-html not escaping HTML code blocks when lacking a language identifier
- Severity:
- High
Description
Any website using discord-markdown with user-generated markdown is vulnerable to having code injected into the page where the markdown is displayed.
Recommendation
Update the discord-markdown package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.3.1
- Patched version(s): 2.3.1
References
Related Issues
- Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML - CVE-2021-41164
- Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML. - CVE-2021-37695
- Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using `Pandas - CVE-2026-41138
- HTML comments vulnerability allowing to execute JavaScript code - CVE-2021-41165
You might also like:
- Tags:
- npm
- discord-markdown
Anything's wrong? Let us know Last updated on January 09, 2023


