Описание
Content injection in marked
Versions 0.3.7 and earlier of marked When mangling is disabled via option mangle don't escape target href. This allow attacker to inject arbitrary html-event into resulting a tag.
Пакеты
Наименование
marked
npm
Затронутые версииВерсия исправления
< 0.3.9
0.3.9