markdown-to-jsx is vulnerable to Cross-site Scripting (XSS)
61
Medium Risk
Affected versions of this package fail to properly sanitize user-supplied input in multiple HTML attributes, enabling stored or reflected XSS attacks. An attacker could exploit this by injecting malicious scripts into web pages, compromising user sessions, or redirecting to phishing sites.
You are affected if you are using a version that falls within the vulnerable range.
markdown-to-jsx is vulnerable to Cross-site Scripting (XSS) in versions 7.0.0 - 7.7.5.
Upgrade the markdown-to-jsx library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant