VDB
Sign up
MEDIUM

GHSA-cfjh-p3g4-3q2f

VBScript Content Injection in marked

Quick fix

GHSA-cfjh-p3g4-3q2f — marked: upgrade to the fixed version with the command below.

npm install marked@0.3.3

Details

Versions 0.3.2 and earlier of `marked` are affected by a cross-site scripting vulnerability even when `sanitize:true` is set.

## Proof of Concept ( IE10 Compatibility Mode Only )

`[xss link](vbscript:alert(1))`

will get a link

`<a href="vbscript:alert(1)">xss link</a>`

## Recommendation

Update to version 0.3.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0Fixed in: 0.3.3
Fixnpm install marked@0.3.3

References