VDB
Sign up
MEDIUM6.1

GHSA-xmr7-v725-2jjr

Cross site scripting in comrak

Details

An issue was discovered in the comrak crate before 0.9.1 for Rust. Cross site scripting (XSS) can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/comrak
Introduced in: 0Fixed in: 0.9.1

Upgrade comrak to 0.9.1 or newer (ecosystem crates.io).

References