PT-2020-21403 · Npmcorp · Marky-Markdown

Published

2020-09-03

·

Updated

2020-09-03

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions marky-markdown versions (all versions)
Description The issue concerns HTML Injection due to the failure to sanitize style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
Recommendations For all versions, upgrade to @npmcorp/marky-markdown, as the original package is no longer maintained.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-MG69-6J3M-JVGW

Affected Products

Marky-Markdown