Vulnerabilities/

markdown-it vulnerable to Inefficient Regular Expression Complexity

Severity:
High

Description

A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue.

Recommendation

Update the markdown-it package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
markdown-it
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing