MEDIUM6.1
GHSA-x3g3-334f-q6h4
Pandao editor.md vulnerable to DOM XSS
Details
pandao Editor.md 1.5.0 has DOM XSS via input starting with a `<<` substring, which is mishandled during construction of an `A` element.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/editor.md
No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.