Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
MEDIUM severity

CVE-2021-39199 — remark-html

MEDIUMFix: remarkjs/remark-html@b75c9dd

CVE-2021-39199 is a medium-severity (CVSS 6.1) Cross-site Scripting (XSS) vulnerability in remark-html. A fix is available for remark-html — see the affected versions and patch details below.

Unsafe defaults in `remark-html`

Also known asGHSA-9q5w-79cv-947m
Published
Updated
Affected
2 pkgs
Patched
2 / 2
Exploits
None indexed
Exploitation data as of Oct 8, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
1.1%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs64th percentile — riskier than 64% of all scored CVEsHighest risk
0.00%0.53%1.05%1.57%0.3%1.1%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2021-39199 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

2 pkgs affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

426other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
remark-htmlnpm
693Kdownloads / week

Description

Impact

The documentation of remark-html has mentioned that it was safe by default. In practise the default was never safe and had to be opted into. This means arbitrary HTML can be passed through leading to potential XSS attacks.

Patches

The problem has been patched in 13.0.2 and 14.0.1: remark-html is now safe by default, and the implementation matches the documentation.

Workarounds

On older affected versions, pass sanitize: true, like so:

-  .use(remarkHtml)
+  .use(remarkHtml, {sanitize: true})

References

n/a

For more information

If you have any questions or comments about this advisory:

Affected Packages

2 total 2 fixed
EcosystemPackageVulnerable rangeFix
📦npmremark-htmlall versions13.0.2npm install remark-html@13.0.2
📦npmremark-html≥ 14.0.0&&< 14.0.114.0.1npm install remark-html@14.0.1

Affected Products

1 product · 2 configurations
Application
remark-htmlremark
≥ 14.0.0 && < 14.0.1
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for remark-html, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update remark-html to 13.0.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-39199 is resolved across your whole dependency graph.

  3. Workarounds

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Frequently Asked Questions

### Impact The documentation of `remark-html` has mentioned that it was safe by default. In practise the default was never safe and had to be opted into. This means arbitrary HTML can be passed through leading to potential XSS attacks. ### Patches The problem has been patched in 13.0.2 and 14.0.1: `remark-html` is now safe by default, and the implementation matches the documentation. ### Workarounds On older affected versions, pass `sanitize: true`, like so: ```diff - .use(remarkHtml) + .use(remarkHtml, {sanitize: true}) ``` ### References n/a ### For more information If you have a
O3 Security · Impact-Aware SCA

Is CVE-2021-39199 in your dependencies?

Find it across npm, including transitive dependencies.

CVE-2021-39199: remark-html XSS — Fixed in 13.0.2