VDB
Sign up
MEDIUM6.1

GHSA-847g-34c5-vvm8

editor.md vulnerable to Cross-site Scripting

Details

Cross Site Scripting (XSS) vulnerability in pandao editor.md thru 1.5.0 allows attackers to inject arbitrary web script or HTML via crafted markdown text.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/editor.md
Introduced in: 0

No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.

References