VDB
Sign up
MEDIUM6.1

GHSA-9cw2-jqp5-7x39

Multiple Content Injection Vulnerabilities in marked

Quick fix

GHSA-9cw2-jqp5-7x39 — marked: upgrade to the fixed version with the command below.

npm install marked@0.3.1

Details

Versions 0.3.0 and earlier of `marked` are affected by two cross-site scripting vulnerabilities, even when `sanitize: true` is set.

The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.

## Recommendation

Upgrade to version 0.3.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0Fixed in: 0.3.1
Fixnpm install marked@0.3.1

References