PT-2020-21207 · Discord · Discord-Markdown
Published
2020-02-24
·
Updated
2020-02-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
discord-markdown versions prior to 2.3.1
Description
The issue affects websites that use discord-markdown with user-generated markdown, making them susceptible to code injection where the markdown is displayed.
Recommendations
For versions prior to 2.3.1, update to version 2.3.1 to resolve the issue.
As a temporary workaround, consider escaping the characters
<, >, and & before sending plain code blocks to discord-markdown. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Discord-Markdown