MEDIUM6.1
GHSA-36m4-6v6m-4vpr
Cross-site Scripting in remarkable
Quick fix
GHSA-36m4-6v6m-4vpr — remarkable: upgrade to the fixed version with the command below.
npm install remarkable@1.7.2Details
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a `\x0ejavascript:` URL.
Are you affected?
Enter the version of the package you're using.