Medium severity6.1NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2014-10065
CVE-2014-10065
Description
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
remarkablenpm | < 1.4.1 | 1.4.1 |
Affected products
3- HackerOne/remarkable node modulev5Range: <1.4.1
- cpe:2.3:a:remarkable_project:remarkable:*:*:*:*:*:node.js:*:*Range: <1.4.1
Patches
Vulnerability mechanics
References
6- nodesecurity.io/advisories/30nvdExploitThird Party Advisory
- github.com/advisories/GHSA-f9vc-q3hh-qhfvghsaADVISORY
- github.com/jonschlinkert/remarkable/issues/97nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2014-10065ghsaADVISORY
- github.com/jonschlinkert/remarkable/commit/d54ed887f4997221cd7cb9790e953a83c504de36ghsaWEB
- www.npmjs.com/advisories/30ghsaWEB
News mentions
0No linked articles in our index yet.