VDB
Sign up
—

GO-2021-0086

Cross-site scripting in github.com/documize/community

Quick fix

GO-2021-0086 — github.com/documize/community: upgrade to the fixed version with the command below.

go get github.com/documize/community@v1.76.3-0.20191119114751-a4384210d4d0

Details

HTML content in markdown is not sanitized during rendering, possibly allowing XSS if used to render untrusted user input.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/documize/community
Introduced in: 0Fixed in: 1.76.3-0.20191119114751-a4384210d4d0
Fixgo get github.com/documize/community@v1.76.3-0.20191119114751-a4384210d4d0

References