Vulnerabilities/

markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped

Severity:
Medium

Description

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
markdown-it-toc
Anything's wrong? Let us know Last updated on January 27, 2023