CVE-2020-7773

Publication date

2020-11-16 12:00:24

Family

snyk

State

PUBLISHED

Description

This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const markdownItHighlightjs = require("markdown-it-highlightjs"); const md = require(markdown-it); const reuslt_xss = md() .use(markdownItHighlightjs, { inline: true }) .render(console.log(42){.">js}); console.log(reuslt_xss);