{"id":"GHSA-9r27-994c-4xch","summary":"discord-html not escaping HTML code blocks when lacking a language identifier","details":"### Impact\nAny website using discord-markdown with user-generated markdown is vulnerable to having code injected into the page where the markdown is displayed.\n\n### Patches\nThis has been patched in version 2.3.1\n\n### Workarounds\nEscape the characters `&lt;&gt;&amp;` before sending plain code blocks to discord-markdown.\n\n### References\nhttps://github.com/brussell98/discord-markdown/issues/13","modified":"2020-02-21T20:20:53Z","published":"2020-02-24T17:34:02Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-02-21T20:20:53Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/brussell98/discord-markdown/security/advisories/GHSA-9r27-994c-4xch"},{"type":"WEB","url":"https://github.com/brussell98/discord-markdown/issues/13"},{"type":"WEB","url":"https://github.com/brussell98/discord-markdown/commit/7ce2eb66520815dcf5e97ef2bc8a2d5979da66e7"}],"affected":[{"package":{"name":"discord-markdown","ecosystem":"npm","purl":"pkg:npm/discord-markdown"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/02/GHSA-9r27-994c-4xch/GHSA-9r27-994c-4xch.json"}}],"schema_version":"1.9.0"}