Intel

AIKIDO-2025-10120

@quasar/quasar-ui-qmarkdown is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2025-43954 Published Feb 28, 2025

45

Medium Risk

This Affects:

js@quasar/quasar-ui-qmarkdown
1.4.0 - 2.0.4
Fixed in 2.0.5
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS) in the extendHeading function, when the no-html option is enabled.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@quasar/quasar-ui-qmarkdown is vulnerable to Cross-site Scripting (XSS) in versions 1.4.0 - 2.0.4.

How to fix this

Upgrade the @quasar/quasar-ui-qmarkdown library to the patch version.