VDB
Sign up
HIGH

GHSA-ccrp-c664-8p4j

Cross-Site Scripting in markdown-to-jsx

Quick fix

GHSA-ccrp-c664-8p4j — markdown-to-jsx: upgrade to the fixed version with the command below.

npm install markdown-to-jsx@6.11.4

Details

Versions of `markdown-to-jsx` prior to 6.11.4 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization the package may render output containing malicious JavaScript. This vulnerability can be exploited through input of links containing `data` or VBScript URIs and a base64-encoded payload.

## Recommendation

Upgrade to version 6.11.4 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/markdown-to-jsx
Introduced in: 0Fixed in: 6.11.4
Fixnpm install markdown-to-jsx@6.11.4

References