Description
Affected versions of marked
are susceptible to a cross-site scripting vulnerability in link components when sanitize:true
is configured.
Recommendation
Update the marked
package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.6
- Patched version(s): 0.3.6
References
Related Issues
- Command Injection in lodash (GHSA-35jh-r3h4-6jhm) - CVE-2021-23337
- Marked allows Regular Expression Denial of Service (ReDoS) attacks - CVE-2018-25110
- Bootstrap Cross-Site Scripting (XSS) vulnerability - CVE-2024-6531
- Regular Expression Denial of Service in jsoneditor - CVE-2021-3822
- Tags:
- npm
- marked
Anything's wrong? Let us know Last updated on September 07, 2023