md-editor-v3 is vulnerable to Cross-Site Scripting (XSS)
53
Medium Risk
The first-party XSS plugin sanitizes raw HTML tokens but not math-token content in the Markdown renderer. On the initial render, before the default KaTeX script loads, the KaTeX plugin emits math content as raw HTML through an innerHTML fallback path. A math-delimited handler therefore bypasses the enabled XSS protection and runs in the host application's origin when a viewer opens the content. The fix escapes the math token content in the pre-KaTeX fallback so it renders as plain text.
You are affected if you are using a version that falls within the vulnerable range and you enable the shipped XSSPlugin to render untrusted Markdown that can contain math delimiters.
md-editor-v3 is vulnerable to Cross-Site Scripting (XSS) in versions 4.11.3 - 6.5.5.
Upgrade the md-editor-v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant