Description
This affects all versions of package markdown-it-toc. The title of the generated toc and the contents of the header are not escaped.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-MARKDOWNITTOC-1044067
Related Vulnerabilities
CVE-2022-25929 Vulnerability in npm package smoothie
CVE-2021-23362 Vulnerability in maven package org.webjars.npm:hosted-git-info
CVE-2021-35065 Vulnerability in maven package org.webjars.npm:glob-parent
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2016-7103 Vulnerability in maven package org.fujion.webjars:jquery-ui