Description
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Remediation
References
https://github.com/jonschlinkert/remarkable/issues/332
Related Vulnerabilities
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http3:http3-qpack
CVE-2022-29078 Vulnerability in npm package ejs
CVE-2020-15500 Vulnerability in npm package tileserver-gl
CVE-2018-3717 Vulnerability in npm package simple-server
CVE-2019-12395 Vulnerability in maven package us.dynmap:dynmap