{"id":"GHSA-xr53-m937-jr9c","summary":"Cross-Site Scripting in ngx-md","details":"Versions of `ngx-md` prior to 6.0.3 are vulnerable to Cross-Site Scripting.  Links are not properly restricted to http/https and can contain JavaScript which may lead to arbitrary code execution. Markdown input such as `[Click Me](javascript:alert('Injected!'%29)` is rendered as a `Click Me` link that executes JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 6.0.3 or later.","modified":"2021-10-04T21:05:25Z","published":"2020-09-03T15:49:14Z","database_specific":{"github_reviewed_at":"2020-08-31T19:01:03Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/dimpu/ngx-md/issues/129"},{"type":"PACKAGE","url":"https://github.com/dimpu/ngx-md"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1485"}],"affected":[{"package":{"name":"ngx-md","ecosystem":"npm","purl":"pkg:npm/ngx-md"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-xr53-m937-jr9c/GHSA-xr53-m937-jr9c.json"}}],"schema_version":"1.9.0"}