Description
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-MARKDOWNITDECORATE-1044068
Related Vulnerabilities
CVE-2020-36180 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-43838 Vulnerability in npm package jsx-slack
CVE-2023-50137 Vulnerability in maven package com.jfinal:jfinal
CVE-2020-7748 Vulnerability in npm package @tsed/core
CVE-2021-41182 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui