HTML Injection in marky-markdown
Moderate severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 9, 2023
All versions of
marky-markdown
are vulnerable to HTML Injection due to a validation bypass. The package only allows iframes where the source isyoutube.com
but it is possible to bypass the validation with sources whereyoutube.com
is the sub-domain, such asyoutube.com.evil.co
. ThisRecommendation
This package is no longer maintained. Please upgrade to
@npmcorp/marky-markdown
References