HIGH
GHSA-mrmf-qwxg-7c3h
XSS in Data URI in remarkable
Quick fix
GHSA-mrmf-qwxg-7c3h — remarkable: upgrade to the fixed version with the command below.
npm install remarkable@1.7.0Details
Affected versions of `remarkable` are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of `data:` URIs in links, and can therefore execute javascript.
## Proof of Concept
```markdown [link](data:text/html,<script>alert('0')</script>) ```
## Recommendation
Update to v1.7.0 or later
Are you affected?
Enter the version of the package you're using.