MEDIUM6.1
GHSA-2j5v-fc74-j9q2
Cross-Site Scripting in editor.md
Details
All versions of `editor.md` are vulnerable to Cross-Site Scripting. User input is insufficiently sanitized, allowing attackers to inject malicious code in payloads containing base64-encoded content.
## Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/editor.md
No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.