Vulnerability library
Security checkJanuary 27, 2023

markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmmarkdown-it-toc

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.

Recommendation

No fix is available yet. Followings are affected versions:

  • <= 1.1.0

References

Could your website be exposed too?

SmartScanner can check your website for markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated January 27, 2023