VDB
Sign up
MEDIUM6.1

GHSA-qj3f-9gmq-fwv5

Cross-Site Scripting in simple-markdown

Quick fix

GHSA-qj3f-9gmq-fwv5 — simple-markdown: upgrade to the fixed version with the command below.

npm install simple-markdown@0.4.4

Details

Versions of `simple-markdown` prior to 0.4.4 are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization the package may render output containing malicious JavaScript. This vulnerability can be exploited through input of links containing `data` or VBScript URIs and a base64-encoded payload.

## Recommendation

Upgrade to version 0.4.4 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/simple-markdown
Introduced in: 0Fixed in: 0.4.4
Fixnpm install simple-markdown@0.4.4

References