Marked: Cross-site Scripting (XSS) via Data URIs - snyk notifications

Created on 4 Mar 2017  Â·  6Comments  Â·  Source: markedjs/marked

✗ High severity vulnerability found on [email protected]

✗ High severity vulnerability found on [email protected]

✗ High severity vulnerability found on [email protected]

Most helpful comment

@chjj @matt- @paulirish Any word on getting a tag for this fix?

All 6 comments

We are waiting for https://github.com/chjj/marked/pull/844 to be pushed by the maintainer.

I am keeping this one open until the change is pushed, but I wanted to rename the ticket to make it more search friendly.

This seems important enough to cut a new release for. Any reason that isn't being done?

@chjj @matt- @paulirish Any word on getting a tag for this fix?

0.3.7 finally came out, and did include the previous submitted fixes. Unfortunately, there's still one high-severity vulnerability that is supposed to be addressed by the upcoming 0.3.9 release.

Believe 0.3.9 corrects all these issues. Please confirm and comment, if incorrect.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

FireflyAndStars picture FireflyAndStars  Â·  3Comments

priyesh-diukar picture priyesh-diukar  Â·  3Comments

toc
zoe-cjf picture zoe-cjf  Â·  3Comments

camwiegert picture camwiegert  Â·  4Comments

eGavr picture eGavr  Â·  4Comments