Description
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-MARKDOWNITDECORATE-1044068
Related Vulnerabilities
CVE-2019-5437 Vulnerability in npm package harp
CVE-2021-23631 Vulnerability in npm package convert-svg-core
CVE-2022-43419 Vulnerability in maven package org.jenkins-ci.plugins:katalon
CVE-2023-45136 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2021-28092 Vulnerability in maven package org.webjars.npm:is-svg