VDB
Sign up
MEDIUM6.1

GHSA-vjcj-5g2r-vxqc

Pandao editor.md vulnerable to XSS in IMG attributes

Details

Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/editor.md

No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.

References