Description
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
Remediation
References
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BO2RMVVZVV6NFTU46B5RYRK7ZCXYARZS/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M6BJG6RGDH7ZWVVAUFBFI5L32RSMQN2S/
https://snyk.io/vuln/npm:marked:20170112
Related Vulnerabilities
CVE-2023-34840 Vulnerability in npm package angular-ui-notification
CVE-2023-33510 Vulnerability in maven package org.jeecgframework.p3:jeecg-p3-biz-chat
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api
CVE-2020-28267 Vulnerability in npm package @strikeentco/set
CVE-2023-22465 Vulnerability in maven package org.http4s:http4s-core_2.12