VDB
Sign up
MEDIUM6.1

GHSA-9g4f-5rpg-4948

NodeBB Cross-site Scripting Vulnerability in Markdown Processing

Quick fix

GHSA-9g4f-5rpg-4948 — nodebb: upgrade to the fixed version with the command below.

npm install nodebb@0.70

Details

Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nodebb
Introduced in: 0Fixed in: 0.70
Fixnpm install nodebb@0.70
npm/nodebb-plugin-markdown
Introduced in: 0Fixed in: 5.1.1
Fixnpm install nodebb-plugin-markdown@5.1.1

References