{"id":"GHSA-xr53-m937-jr9c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xr53-m937-jr9c","summary":"Cross-Site Scripting in ngx-md","details":"Versions of `ngx-md` prior to 6.0.3 are vulnerable to Cross-Site Scripting.  Links are not properly restricted to http/https and can contain JavaScript which may lead to arbitrary code execution. Markdown input such as `[Click Me](javascript:alert('Injected!'%29)` is rendered as a `Click Me` link that executes JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 6.0.3 or later.","published":"2020-09-03T15:49:14Z","modified":"2021-10-04T21:05:25Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ngx-md","fixedVersion":"6.0.3"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/dimpu/ngx-md/issues/129"},{"type":"PACKAGE","url":"https://github.com/dimpu/ngx-md"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1485"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-10-04T21:05:25Z"}}