{"id":"GHSA-f9vc-q3hh-qhfv","summary":"Content Injection in remarkable","details":"Versions 1.4.0 and earlier of `remarkable` are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of `remarkable` did not properly whitelist link protocols, and consequently allowed `javascript:` to be used. \n\n\n### Proof of Concept\n\nMarkdown Source:\n```\n[link](\u003cjavascript:alert(1)\u003e)\n```\n\nRendered HTML:\n```\n\u003ca href=\"javascript:alert(1)\"\u003elink\u003c/a\u003e\n```\n\n\n## Recommendation\n\nUpdate to version 1.4.1 or later","aliases":["CVE-2014-10065"],"modified":"2023-11-08T03:57:33.593508Z","published":"2020-08-31T22:56:00Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:08:29Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-10065"},{"type":"WEB","url":"https://github.com/jonschlinkert/remarkable/issues/97"},{"type":"WEB","url":"https://github.com/jonschlinkert/remarkable/commit/d54ed887f4997221cd7cb9790e953a83c504de36"},{"type":"WEB","url":"https://www.npmjs.com/advisories/30"}],"affected":[{"package":{"name":"remarkable","ecosystem":"npm","purl":"pkg:npm/remarkable"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-f9vc-q3hh-qhfv/GHSA-f9vc-q3hh-qhfv.json"}}],"schema_version":"1.9.0"}