MEDIUM6.1
GHSA-x65c-4fgj-5fc3
Cross-site Scripting in pandao
Details
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/editor.md
No fixed version published yet for editor.md (npm). Pin to a known-safe version or switch to an alternative.