Description
All versions of marky-markdown are vulnerable to HTML Injection. The package fails to sanitize style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Related Issues
- HTML Injection in marky-markdown - Vulnerability
- HTML tag injection - Vulnerability
- XSS/HTML Injection Vulnerability in Umbraco Backoffice Components - CVE-2025-24012
- HTML Injection in preact - Vulnerability
You might also like:
- Tags:
- npm
- marky-markdown
Anything's wrong? Let us know Last updated on January 09, 2023


