MEDIUM6.1
GHSA-qj3f-9gmq-fwv5
Cross-Site Scripting in simple-markdown
Quick fix
GHSA-qj3f-9gmq-fwv5 — simple-markdown: upgrade to the fixed version with the command below.
npm install simple-markdown@0.4.4Details
Versions of `simple-markdown` prior to 0.4.4 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization the package may render output containing malicious JavaScript. This vulnerability can be exploited through input of links containing `data` or VBScript URIs and a base64-encoded payload.
## Recommendation
Upgrade to version 0.4.4 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-9844[ADVISORY]
- https://github.com/Khan/simple-markdown/pull/63[WEB]
- https://github.com/Khan/simple-markdown[PACKAGE]
- https://github.com/advisories/GHSA-qj3f-9gmq-fwv5[ADVISORY]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JFLP3KJVSV5VWMNEBRXLGRVYFXOV5KOG[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KZG2I7VH7WLSEUQ77KYP5CRAVFT2RK2U[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O5EFW655O3BXZYAPB65XEREXB2DSNSOT[WEB]
- https://www.npmjs.com/advisories/815[WEB]
- https://www.npmjs.com/package/simple-markdown/v/0.4.4[WEB]