Skip to content

Commit df906fe

Browse files
authored
Update mdast-util-to-hast version to 13.2.1
CVE-2025-66400: mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user-supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1. Medium Vulnerability. Signed-off-by: Skúli Arnlaugsson <[email protected]>
1 parent fda7fa5 commit df906fe

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@
5353
"devlop": "^1.0.0",
5454
"hast-util-to-jsx-runtime": "^2.0.0",
5555
"html-url-attributes": "^3.0.0",
56-
"mdast-util-to-hast": "^13.0.0",
56+
"mdast-util-to-hast": "^13.2.1",
5757
"remark-parse": "^11.0.0",
5858
"remark-rehype": "^11.0.0",
5959
"unified": "^11.0.0",

0 commit comments

Comments
 (0)