VYPR

Markdown To Jsx

by Quantizor

Source repositories

CVEs (2)

  • CVE-2024-56082LowDec 15, 2024
    risk 0.16cvss 3.5epss 0.00

    ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.

  • CVE-2024-21535Oct 15, 2024
    risk 0.00cvss epss 0.00

    Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.