Vulnerabilities/

Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc

Severity:
High

Description

An unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the javascript: protocol scheme in the URL.

Recommendation

Update the @nuxtjs/mdc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@nuxtjs/mdc
Anything's wrong? Let us know Last updated on February 06, 2025

This issue is available in SmartScanner Professional

See Pricing