markdown-to-jsx is vulnerable to Improper Input Validation
30
Low Risk
Affected versions of this package are vulnerable to Improper Input Validation, characterized by insufficient URL sanitization against javascript:, vbscript:, and malicious data: URLs, and the default disabling of tagfilter, which escapes dangerous HTML tags in both HTML and React output. An attacker could exploit this by crafting and injecting malicious input that bypasses these protections, leading to cross-site scripting (XSS) attacks or other client-side code-execution vulnerabilities.
You are affected if you are using a version that falls within the vulnerable range.
markdown-to-jsx is vulnerable to Improper Input Validation in versions 7.0.0 - 8.0.0.
Upgrade the markdown-to-jsx library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant