VDB
Sign up
MEDIUM6.1

GHSA-vfvf-mqq8-rwqc

Sanitization bypass using HTML Entities in marked

Quick fix

GHSA-vfvf-mqq8-rwqc — marked: upgrade to the fixed version with the command below.

npm install marked@0.3.6

Details

Affected versions of `marked` are susceptible to a cross-site scripting vulnerability in link components when `sanitize:true` is configured.

## Proof of Concept

This flaw exists because link URIs containing HTML entities get processed in an abnormal manner. Any HTML Entities get parsed on a best-effort basis and included in the resulting link, while if that parsing fails that character is omitted.

For example:

A link URI such as ``` javascript&#x58document;alert(1) ``` Renders a valid link that when clicked will execute `alert(1)`.

## Recommendation

Update to version 0.3.6 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/marked
Introduced in: 0Fixed in: 0.3.6
Fixnpm install marked@0.3.6

References