Intel

AIKIDO-2024-10034

markdown-it is vulnerable to Infinite Loop

Infinite Loop Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 19, 2024

74

High Risk

This Affects:

JSmarkdown-it
13.0.0 - 13.0.1
Fixed in 13.0.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to an infinite loop in the linkify inline rule when processing malformed input.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

markdown-it is vulnerable to Infinite Loop in versions 13.0.0 - 13.0.1.

How to fix this

Upgrade the markdown-it library to the patch version.