OSV 1.4.0 · github-reviewed · 修改于 2021-10-05 04:55
发布时间
2020-09-03 23:45
GitHub 审查时间
2020-09-01 03:00
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-mg69-6j3m-jvgw/GHSA-mg69-6j3m-jvgw.json
All versions of marky-markdown are vulnerable to HTML Injection. The package fails to sanitize style attributes in img tags of the markdown input. This may allow attackers to affect the size of images in the rendered HTML.
This package is no longer maintained. Please upgrade to @npmcorp/marky-markdown