HIGH7.3
GHSA-mg69-6j3m-jvgw
HTML Injection in marky-markdown
Details
All versions of `marky-markdown` are vulnerable to HTML Injection. The package fails to sanitize `style` attributes in `img` tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
## Recommendation
This package is no longer maintained. Please upgrade to `@npmcorp/marky-markdown`
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/marky-markdown
Introduced in:
0.0.0No fixed version published yet for marky-markdown (npm). Pin to a known-safe version or switch to an alternative.