Reflected cross-site scripting (XSS) In remarkable
Description
XSS in Data URI in remarkable
Affected versions of remarkable are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of data: URIs in links, and can therefore execute javascript.
Proof of Concept
[link](data:text/html,<script>alert('0')</script>)
Recommendation
Update to v1.7.0 or later
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 1.7.0 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.