The package is fast yet-another-markdown-parser, pure Ruby, using a strict syntax definition and supporting several common extensions.
Security Fix(es):
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.(CVE-2021-28834)
{ "severity": "Critical" }