VDB
Sign up
HIGH

GHSA-f9vc-q3hh-qhfv

Content Injection in remarkable

Quick fix

GHSA-f9vc-q3hh-qhfv — remarkable: upgrade to the fixed version with the command below.

npm install remarkable@1.4.1

Details

Versions 1.4.0 and earlier of `remarkable` are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of `remarkable` did not properly whitelist link protocols, and consequently allowed `javascript:` to be used.

### Proof of Concept

Markdown Source: ``` [link](<javascript:alert(1)>) ```

Rendered HTML: ``` <a href="javascript:alert(1)">link</a> ```

## Recommendation

Update to version 1.4.1 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/remarkable
Introduced in: 0Fixed in: 1.4.1
Fixnpm install remarkable@1.4.1

References