Headline
GHSA-rhf5-2378-3w3w: markdown-it-decorate vulnerable to cross-site scripting (XSS)
markdown-it-decorate adds attributes, IDs and classes to Markdown, and the most recent version 1.2.2 was published in 2017. All versions are currently vulnerable to cross-site scripting (XSS) and there is no fixed version at this time.
markdown-it-decorate vulnerable to cross-site scripting (XSS)
Moderate severity GitHub Reviewed Published Jul 19, 2022 • Updated Jul 19, 2022