Vulnerabilities/

XSS in Data URI in remarkable

Severity:
High

Description

Affected versions of remarkable are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of data: URIs in links, and can therefore execute javascript.

Recommendation

Update the remarkable package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
remarkable
Anything's wrong? Let us know Last updated on September 08, 2023