All versions of marky-markdown
are vulnerable to HTML Injection. The package fails to sanitize style
attributes in img
tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
This package is no longer maintained. Please upgrade to @npmcorp/marky-markdown
{ "nvd_published_at": null, "cwe_ids": [ "CWE-79" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-08-31T19:00:28Z" }