OSV 1.4.0 · github-reviewed · 修改于 2021-10-05 04:56
发布时间
2020-09-03 23:45
GitHub 审查时间
2020-09-01 03:00
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-pxmp-fwjc-4x7q/GHSA-pxmp-fwjc-4x7q.json
All versions of marky-markdown are vulnerable to HTML Injection due to a validation bypass. The package only allows iframes where the source is youtube.com but it is possible to bypass the validation with sources where youtube.com is the sub-domain, such as youtube.com.evil.co. This
This package is no longer maintained. Please upgrade to @npmcorp/marky-markdown