VYPR

@digitalocean/do Markdownit

Sign in to watch

by Digital Project

CVEs (1)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-597170.000.00Sep 19, 2025In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).