VDB
Sign up
MEDIUM6.8

GHSA-q3wr-qw3g-3p4h

Injection/XSS in Redcarpet

Quick fix

GHSA-q3wr-qw3g-3p4h — redcarpet: upgrade to the fixed version with the command below.

bundle update redcarpet

Details

Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the `:escape_html` option was being used. This is fixed in version 3.5.1 by the referenced commit.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/redcarpet
Introduced in: 0Fixed in: 3.5.1
Fixbundle update redcarpet

References