{"id":"GHSA-hpr5-wp7c-hh5q","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hpr5-wp7c-hh5q","summary":"Cross-Site Scripting in mrk.js","details":"Versions of `mrk.js` before 2.0.1 are vulnerable to cross-site scripting (XSS) when markdown is converted to HTML.\n\n\n## Recommendation\n\nUpdate to version 2.0.1 or later and use `mark.sanitizeURL()` for any `src` and `href` attributes when extending the markdown.","published":"2020-09-01T19:37:29Z","modified":"2021-09-23T21:50:21Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"mrk.js","fixedVersion":"2.0.1"}],"fix":{"url":"https://github.com/heyitsmeuralex/mrk/pull/3","label":"heyitsmeuralex/mrk#3"},"references":[{"type":"WEB","url":"https://github.com/heyitsmeuralex/mrk/pull/3"},{"type":"PACKAGE","url":"https://github.com/heyitsmeuralex/mrk"},{"type":"WEB","url":"https://www.npmjs.com/advisories/587"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-09-23T21:50:21Z"}}