VDB
Sign up
MEDIUM6.1

GHSA-3rm2-h79c-8qw6

md-editor-v3: XSS via fenced-code language rendering bypass

Quick fix

GHSA-3rm2-h79c-8qw6 — md-editor-v3: upgrade to the fixed version with the command below.

npm install md-editor-v3@6.5.4

Details

### Summary `MdPreview` interpolates a fenced-code language into HTML attributes without escaping it. A crafted info string therefore executes JavaScript even when the shipped `XSSPlugin` is enabled.

### Details `useMarkdownIt()` (`packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts:206`) registers a `highlight` callback whose final return inserts `language` into both `class="language-${language}"` and an unquoted `language=${language}` attribute without escaping. Both highlighting paths reach this return. `XSSPlugin()` filters only existing `html_block` and `html_inline` tokens before rendering, so it cannot inspect this renderer-generated HTML.

### PoC The Vue application enables the shipped `XSSPlugin` and renders attacker-controlled Markdown. `noHighlight: true` only makes reproduction deterministic; the default highlighting path reaches the same unsafe return. Use this as `src/main.js`:

```js import { createApp, h } from 'vue'; import { MdPreview, XSSPlugin, config } from 'md-editor-v3';

config({ markdownItPlugins: p => [...p, { type: 'xss', plugin: XSSPlugin, options: {} }] }); const markdown = '```x"><details/open/ontoggle=alert(document.domain)>\nSAFE\n```'; createApp({ render: () => h(MdPreview, { editorId: 'poc', modelValue: markdown, noHighlight: true }) }).mount('#app'); ```

Create and run the app, replacing `src/main.js` when indicated:

```sh npm create vite@latest poc -- --template vue cd poc npm install npm install md-editor-v3@6.5.3 # Replace src/main.js with the code above. npm run dev ```

Opening the displayed URL automatically shows the application hostname in an alert.

### Impact An attacker who can supply Markdown can execute JavaScript in the application origin when a victim renders it. If the host stores that Markdown, this becomes stored XSS.

### Suggested fix Escape `language` with `md.utils.escapeHtml` before interpolation and quote the `language` attribute. Add this payload and the raw control as regression tests with `XSSPlugin` enabled.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/md-editor-v3
Introduced in: 0Fixed in: 6.5.4
Fixnpm install md-editor-v3@6.5.4

References