Description
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-MARKDOWNITDECORATE-1044068
Related Vulnerabilities
CVE-2020-7678 Vulnerability in npm package node-import
CVE-2010-1587 Vulnerability in maven package org.apache.activemq:apache-activemq
CVE-2020-6950 Vulnerability in maven package org.glassfish:jakarta.faces
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.mergewith
CVE-2021-43849 Vulnerability in npm package cordova-plugin-fingerprint-aio