Description
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Remediation
References
https://github.com/jonschlinkert/remarkable/issues/332
Related Vulnerabilities
CVE-2023-26474 Vulnerability in maven package org.xwiki.platform:xwiki-platform-legacy-oldcore
CVE-2020-7690 Vulnerability in maven package org.webjars.npm:jspdf
CVE-2022-41255 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt
CVE-2020-7746 Vulnerability in maven package org.webjars.bowergithub.chartjs:chart.js
CVE-2017-16116 Vulnerability in maven package org.webjars.npm:string