CVE-2020-28459 Information

Description

This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.

Reference

https://security.snyk.io/vuln/SNYK-JS-MARKDOWNITDECORATE-1044068

Share on: