VDB
Sign up
MEDIUM6.1

GHSA-x65c-4fgj-5fc3

Cross-site Scripting in pandao

Details

pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/editor.md

No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.

References