MEDIUM6.1
GHSA-9cw2-jqp5-7x39
Multiple Content Injection Vulnerabilities in marked
Quick fix
GHSA-9cw2-jqp5-7x39 — marked: upgrade to the fixed version with the command below.
npm install marked@0.3.1Details
Versions 0.3.0 and earlier of `marked` are affected by two cross-site scripting vulnerabilities, even when `sanitize: true` is set.
The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.
## Recommendation
Upgrade to version 0.3.1 or later.
Are you affected?
Enter the version of the package you're using.