Medium severity6.1NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2017-16006
CVE-2017-16006
Description
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of data: URIs in links and can therefore execute javascript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
remarkablenpm | < 1.7.0 | 1.7.0 |
Affected products
3- HackerOne/remarkable node modulev5Range: <=1.6.2
- cpe:2.3:a:remarkable_project:remarkable:*:*:*:*:*:node.js:*:*Range: <=1.6.2
Patches
Vulnerability mechanics
References
5- github.com/jonschlinkert/remarkable/issues/227nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- nodesecurity.io/advisories/319nvdExploitThird Party Advisory
- github.com/advisories/GHSA-mrmf-qwxg-7c3hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-16006ghsaADVISORY
- www.npmjs.com/advisories/319ghsaWEB
News mentions
0No linked articles in our index yet.