{"id":"GHSA-32vw-r77c-gm67","summary":"Withdrawn Advisory: marked cross-site scripting vulnerability","details":"Versions 0.3.2 and earlier of marked are affected by a cross-site scripting vulnerability even when sanitize:true is set.","modified":"2025-02-26T15:25:30Z","published":"2020-08-03T17:57:05Z","withdrawn":"2020-08-03T17:57:05Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2019-06-05T13:58:26Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/markedjs/marked/issues/492"},{"type":"WEB","url":"https://github.com/markedjs/marked/commit/fc372d1c6293267722e33f2719d57cebd67b3da1"},{"type":"WEB","url":"https://www.npmjs.com/advisories/24"},{"type":"WEB","url":"https://www.npmjs.com/advisories/24/versions"}],"affected":[{"package":{"name":"marked","ecosystem":"npm","purl":"pkg:npm/marked"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-32vw-r77c-gm67/GHSA-32vw-r77c-gm67.json"}}],"schema_version":"1.9.0"}