CVE-2021-39199 is a medium-severity (CVSS 6.1) Cross-site Scripting (XSS) vulnerability in remark-html. A fix is available for remark-html — see the affected versions and patch details below.
Unsafe defaults in `remark-html`
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-39199 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
remark-htmlnpmDescription
Impact
The documentation of remark-html has mentioned that it was safe by default. In practise the default was never safe and had to be opted into. This means arbitrary HTML can be passed through leading to potential XSS attacks.
Patches
The problem has been patched in 13.0.2 and 14.0.1: remark-html is now safe by default, and the implementation matches the documentation.
Workarounds
On older affected versions, pass sanitize: true, like so:
- .use(remarkHtml)
+ .use(remarkHtml, {sanitize: true})
References
n/a
For more information
If you have any questions or comments about this advisory:
- Open an issue in
remark-html - Email us at [email protected]
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | remark-html | all versions | 13.0.2npm install remark-html@13.0.2 |
| 📦npm | remark-html | ≥ 14.0.0&&< 14.0.1 | 14.0.1npm install remark-html@14.0.1 |
Affected Products
remark-htmlremarkDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for remark-html, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update remark-html to 13.0.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-39199 is resolved across your whole dependency graph.
Workarounds
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Frequently Asked Questions
Is CVE-2021-39199 in your dependencies?
Find it across npm, including transitive dependencies.