CVE-2020-28459

Publication date

2022-07-25 14:05:43

Family

snyk

State

PUBLISHED

Description

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.