Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgm8-mvfh-rj89

Опубликовано: 21 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs.

This issue affects markdown-it: 14.1.0.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs.

This issue affects markdown-it: 14.1.0.

EPSS

Процентиль: 14%
0.00047
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
3 дня назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs. This issue affects markdown-it: 14.1.0.

CVSS3: 6.3
redhat
3 дня назад

No description is available for this CVE.

nvd
3 дня назад

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs. This issue affects markdown-it: 14.1.0.

debian
3 дня назад

Improper Neutralization of Input During Web Page Generation (XSS or 'C ...

EPSS

Процентиль: 14%
0.00047
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-79