Medium severity6.1OSV Advisory· Published Apr 9, 2019· Updated Jun 17, 2026
CVE-2019-9844
CVE-2019-9844
Description
simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
simple-markdownnpm | < 0.4.4 | 0.4.4 |
Affected products
4- Range: 0.0.9, 0.1.0, 0.1.1, …
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
11- github.com/Khan/simple-markdown/pull/63nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-qj3f-9gmq-fwv5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-9844ghsaADVISORY
- www.npmjs.com/package/simple-markdown/v/0.4.4nvdThird Party AdvisoryWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/JFLP3KJVSV5VWMNEBRXLGRVYFXOV5KOGghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/KZG2I7VH7WLSEUQ77KYP5CRAVFT2RK2UghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/O5EFW655O3BXZYAPB65XEREXB2DSNSOTghsaWEB
- www.npmjs.com/advisories/815ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JFLP3KJVSV5VWMNEBRXLGRVYFXOV5KOG/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZG2I7VH7WLSEUQ77KYP5CRAVFT2RK2U/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O5EFW655O3BXZYAPB65XEREXB2DSNSOT/nvd
News mentions
0No linked articles in our index yet.