HIGH
GHSA-f9vc-q3hh-qhfv
Content Injection in remarkable
Quick fix
GHSA-f9vc-q3hh-qhfv — remarkable: upgrade to the fixed version with the command below.
npm install remarkable@1.4.1Details
Versions 1.4.0 and earlier of `remarkable` are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of `remarkable` did not properly whitelist link protocols, and consequently allowed `javascript:` to be used.
### Proof of Concept
Markdown Source: ``` [link](<javascript:alert(1)>) ```
Rendered HTML: ``` <a href="javascript:alert(1)">link</a> ```
## Recommendation
Update to version 1.4.1 or later
Are you affected?
Enter the version of the package you're using.