Description
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Remediation
References
https://github.com/jonschlinkert/remarkable/issues/332
Related Vulnerabilities
CVE-2019-10805 Vulnerability in npm package valib
CVE-2022-29219 Vulnerability in npm package @chainsafe/lodestar
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core
CVE-2013-6235 Vulnerability in maven package com.jamonapi:jamon
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.freemarker