VDB
Sign up
HIGH7.5

GHSA-hjcp-j389-59ff

Regular Expression Denial of Service in marked

Quick fix

GHSA-hjcp-j389-59ff — marked: upgrade to the fixed version with the command below.

npm install marked@0.3.4

Details

Versions 0.3.3 and earlier of `marked` are affected by a regular expression denial of service ( ReDoS ) vulnerability when passed inputs that reach the `em` inline rule.

## Recommendation

Update to version 0.3.4 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0Fixed in: 0.3.4
Fixnpm install marked@0.3.4

References