CVE-2014-10065
EPSS 0.24%Content Injection in remarkable
Published: 8/31/2020Modified: 11/8/2023
Also known as:GHSA-f9vc-q3hh-qhfv
Description
Versions 1.4.0 and earlier of `remarkable` are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of `remarkable` did not properly whitelist link protocols, and consequently allowed `javascript:` to be used. ### Proof of Concept Markdown Source: ``` [link](<javascript:alert(1)>) ``` Rendered HTML: ``` <a href="javascript:alert(1)">link</a> ``` ## Recommendation Update to version 1.4.1 or later
Affected packages (1)
- npm/remarkablefrom 0, < 1.4.1