Medium severity6.1NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2017-16019
CVE-2017-16019
Description
GitBook is a command line tool (and Node.js library) for building beautiful books using GitHub/Git and Markdown (or AsciiDoc). Stored Cross-Site-Scripting (XSS) is possible in GitBook before 3.2.2 by including code outside of backticks in any ebook. This code will be executed on the online reader.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
gitbooknpm | < 3.2.2 | 3.2.2 |
Affected products
3- HackerOne/gitbook node modulev5Range: <3.2.2
Patches
Vulnerability mechanics
References
5- github.com/GitbookIO/gitbook/issues/1609nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-5h5r-23r4-m87hghsaADVISORY
- nodesecurity.io/advisories/159nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-16019ghsaADVISORY
- www.npmjs.com/advisories/159ghsaWEB
News mentions
0No linked articles in our index yet.