Description
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Remediation
References
https://github.com/jonschlinkert/remarkable/issues/332
Related Vulnerabilities
CVE-2022-2216 Vulnerability in npm package parse-url
CVE-2021-42227 Vulnerability in npm package kindeditor
CVE-2023-30521 Vulnerability in maven package org.jenkins-ci.plugins:assembla-merge-request-builder
CVE-2022-24785 Vulnerability in npm package moment
CVE-2020-21125 Vulnerability in maven package com.bstek.ureport:ureport2-console