HIGH
GHSA-ccrp-c664-8p4j
Cross-Site Scripting in markdown-to-jsx
Quick fix
GHSA-ccrp-c664-8p4j — markdown-to-jsx: upgrade to the fixed version with the command below.
npm install markdown-to-jsx@6.11.4Details
Versions of `markdown-to-jsx` prior to 6.11.4 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization the package may render output containing malicious JavaScript. This vulnerability can be exploited through input of links containing `data` or VBScript URIs and a base64-encoded payload.
## Recommendation
Upgrade to version 6.11.4 or later.
Are you affected?
Enter the version of the package you're using.