Description
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.
Remediation
References
https://nodesecurity.io/advisories/319
https://github.com/jonschlinkert/remarkable/issues/227
Related Vulnerabilities
CVE-2019-12043 Vulnerability in npm package remarkable
CVE-2022-31160 Vulnerability in npm package jquery-ui
CVE-2023-41046 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2021-39234 Vulnerability in maven package org.apache.ozone:ozone-common
CVE-2020-7788 Vulnerability in maven package org.webjars.npm:ini