Description
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.0
References
Could your website be exposed too?
SmartScanner can check your website for markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript - CVE-2019-16763
- Cross-site Scripting in markdown-it-highlightjs - CVE-2020-7773
- Cross site scripting in valine - CVE-2020-28847
- Cross-site scripting in Joplin - joplin - CVE-2020-28249
You might also like:
See something that needs correcting? Let us knowUpdated January 27, 2023


