MEDIUM
GHSA-cfjh-p3g4-3q2f
VBScript Content Injection in marked
Quick fix
GHSA-cfjh-p3g4-3q2f — marked: upgrade to the fixed version with the command below.
npm install marked@0.3.3Details
Versions 0.3.2 and earlier of `marked` are affected by a cross-site scripting vulnerability even when `sanitize:true` is set.
## Proof of Concept ( IE10 Compatibility Mode Only )
`[xss link](vbscript:alert(1))`
will get a link
`<a href="vbscript:alert(1)">xss link</a>`
## Recommendation
Update to version 0.3.3 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-1370[ADVISORY]
- https://github.com/chjj/marked/issues/492[WEB]
- https://github.com/markedjs/marked/issues/492[WEB]
- https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1ba[WEB]
- https://github.com/markedjs/marked/commit/fc372d1c6293267722e33f2719d57cebd67b3da1[WEB]
- https://github.com/markedjs/marked[PACKAGE]
- https://www.npmjs.com/advisories/24[WEB]
- https://www.npmjs.com/advisories/24/versions[WEB]
- http://www.openwall.com/lists/oss-security/2015/01/23/2[WEB]