Description
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Remediation
References
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/
https://snyk.io/vuln/npm:marked:20170112
Related Vulnerabilities
CVE-2021-25987 Vulnerability in npm package hexo
CVE-2023-29526 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-24376 Vulnerability in npm package git-promise
CVE-2018-1999024 Vulnerability in npm package mathjax
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.validation