Vulnerabilities/

Unsafe defaults in `remark-html`

Severity:
High

Description

The documentation of remark-html has mentioned that it was safe by default. In practise the default was never safe and had to be opted into. This means arbitrary HTML can be passed through leading to potential XSS attacks.

Recommendation

Update the remark-html package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
remark-html
Anything's wrong? Let us know Last updated on February 01, 2023