md-editor-v3 is vulnerable to Cross-site Scripting (XSS)
59
Medium Risk
Affected versions of this package are vulnerable to cross-site scripting (XSS) when rendering code blocks due to insufficient sanitization of user input. Malicious content embedded within code blocks may be interpreted and executed by the browser, allowing attackers to inject arbitrary scripts and potentially compromise user sessions or perform unauthorized actions. Proper input sanitization is required to ensure code blocks are safely rendered as plain text without executing embedded HTML or JavaScript.
You are affected if you are using a version that falls within the vulnerable range.
md-editor-v3 is vulnerable to Cross-site Scripting (XSS) in versions 4.15.0 - 5.8.2.
Upgrade the md-editor-v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant