Description
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Remediation
References
https://github.com/jonschlinkert/remarkable/issues/332
Related Vulnerabilities
CVE-2017-16124 Vulnerability in npm package node-server-forfront
CVE-2022-31191 Vulnerability in maven package org.dspace:dspace-jspui
CVE-2018-1000616 Vulnerability in maven package org.onosproject:onos-cli
CVE-2022-1243 Vulnerability in npm package urijs
CVE-2023-46654 Vulnerability in maven package org.jenkins-ci.plugins:electricflow