GHSA-4wx3-54gh-9fr9
GitHub Security Advisory
Cross site scripting in markdown-to-jsx
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.
Affected Packages
npm
markdown-to-jsx
Affected versions:
0
(fixed in 7.4.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.