Описание
HTML Injection in marky-markdown
All versions of marky-markdown are vulnerable to HTML Injection. The package fails to sanitize style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
Recommendation
This package is no longer maintained. Please upgrade to @npmcorp/marky-markdown
Пакеты
Наименование
marky-markdown
npm
Затронутые версииВерсия исправления
>= 0.0.0
Отсутствует
7.3 High
CVSS3
Дефекты
CWE-79
7.3 High
CVSS3
Дефекты
CWE-79