MEDIUM6.1
GHSA-7px7-7xjx-hxm8
Marked vulnerable to XSS from data URIs
Quick fix
GHSA-7px7-7xjx-hxm8 — marked: upgrade to the fixed version with the command below.
npm install marked@0.3.7Details
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000427[ADVISORY]
- https://github.com/advisories/GHSA-7px7-7xjx-hxm8[ADVISORY]
- https://github.com/markedjs/marked[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S[WEB]
- https://snyk.io/vuln/npm:marked:20170112[WEB]