Vulnerabilities/

Sanitization bypass using HTML Entities in marked

Severity:
Medium

Description

Affected versions of marked are susceptible to a cross-site scripting vulnerability in link components when sanitize:true is configured.

Recommendation

Update the marked package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
marked
Anything's wrong? Let us know Last updated on September 07, 2023

This issue is available in SmartScanner Professional

See Pricing