VYPR

earmark

by Pragdave

CVEs (1)

  • CVE-2026-48591Jun 17, 2026
    risk 0.00cvss epss

    Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site scripting via unescaped HTML attribute values. 'Elixir.Earmark.Transform':_make_att1/2 in lib/earmark/transform.ex splices attribute values verbatim between…