Description
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
Remediation
References
https://security.snyk.io/vuln/SNYK-JS-MARKDOWNITDECORATE-1044068
Related Vulnerabilities
CVE-2020-8175 Vulnerability in maven package org.webjars.npm:jpeg-js
CVE-2023-26105 Vulnerability in npm package utilities
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-base
CVE-2020-7656 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery
CVE-2023-6134 Vulnerability in maven package org.keycloak:keycloak-services