VDB
Sign up
HIGH7.3

GHSA-mg69-6j3m-jvgw

HTML Injection in marky-markdown

Details

All versions of `marky-markdown` are vulnerable to HTML Injection. The package fails to sanitize `style` attributes in `img` tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.

## Recommendation

This package is no longer maintained. Please upgrade to `@npmcorp/marky-markdown`

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marky-markdown
Introduced in: 0.0.0

No fixed version published yet for marky-markdown (npm). Pin to a known-safe version or switch to an alternative.

References