markdown-it-decorate vulnerable to cross-site scripting (XSS)
Moderate severity
GitHub Reviewed
Published
Jul 19, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published to the GitHub Advisory Database
Jul 19, 2022
Reviewed
Jul 19, 2022
Published by the National Vulnerability Database
Jul 25, 2022
Last updated
Jan 30, 2023
markdown-it-decorate adds attributes, IDs and classes to Markdown, and the most recent version 1.2.2 was published in 2017. All versions are currently vulnerable to cross-site scripting (XSS) and there is no fixed version at this time
References