Vulnerabilities/

Marp Core allows XSS by improper neutralization of HTML sanitization

Severity:
Medium

Description

Marp Core (@marp-team/marp-core) from v3.0.2 to v3.9.0 and v4.0.0, are vulnerable to cross-site scripting (XSS) due to improper neutralization of HTML sanitization.

Recommendation

Update the @marp-team/marp-core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@marp-team/marp-core
Anything's wrong? Let us know Last updated on December 26, 2024

This issue is available in SmartScanner Professional

See Pricing