Description
All versions of marky-markdown are vulnerable to HTML Injection. The package fails to sanitize style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.0.0
References
Could your website be exposed too?
SmartScanner can check your website for HTML Injection in marky-markdown - marky-markdown and gives you actionable findings to investigate.
Start a free scanRelated Issues
- HTML Injection in marky-markdown - Vulnerability
- HTML tag injection - Vulnerability
- XSS/HTML Injection Vulnerability in Umbraco Backoffice Components - CVE-2025-24012
- HTML Injection in preact - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


