VDB
Sign up
HIGH8.1

GHSA-62m3-fc7f-jpp8

Parsedown Class-Name Injection

Quick fix

GHSA-62m3-fc7f-jpp8 — erusev/parsedown: upgrade to the fixed version with the command below.

composer require erusev/parsedown:^1.7.2

Details

Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary JavaScript code if a script (already running on the affected page) executes the contents of any element with a specific class. This occurs because spaces are permitted in code block infostrings, which interferes with the intended behavior of a single class name beginning with the language- substring.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/erusev/parsedown
Introduced in: 0Fixed in: 1.7.2
Fixcomposer require erusev/parsedown:^1.7.2

References