Vulnerabilities/

HTML Injection in marky-markdown - marky-markdown

Severity:
High

Description

All versions of marky-markdown are vulnerable to HTML Injection. The package fails to sanitize style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
marky-markdown
Anything's wrong? Let us know Last updated on January 09, 2023