Reflected cross-site scripting (XSS) In node-marked
Description
Multiple Content Injection Vulnerabilities in marked
Versions 0.3.0 and earlier of marked are affected by two cross-site scripting vulnerabilities, even when sanitize: true is set.
The attack vectors for this vulnerability are GFM Codeblocks and JavaScript URLs.
Recommendation
Upgrade to version 0.3.1 or later.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 0.3.1+dfsg-1 | ||
nuget | 0.3.2 | ||
debian 11 | 0.3.1+dfsg-1 | ||
debian 14 | 0.3.1+dfsg-1 | ||
npm | 0.3.1 | ||
debian 13 | 0.3.1+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4.