Description
Affected versions of remarkable are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of data: URIs in links, and can therefore execute javascript.
Recommendation
Update the remarkable package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.6.2
- Patched version(s): 1.7.0
References
Related Issues
- Marked vulnerable to XSS from data URIs - CVE-2017-1000427
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
- Cross Site Scripting (XSS) in plotly.js - CVE-2017-1000006
- i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes - CVE-2026-41692
You might also like:
- Tags:
- npm
- remarkable
Anything's wrong? Let us know Last updated on September 08, 2023


