CVE-2024-56082 Information
Dec 16, 2024
cve
Description
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.
Reference
https://github.com/andrewnguonly/Lumos/issues/193 https://github.com/andrewnguonly/Lumos/releases/tag/1.0.17 https://github.com/quantizor/markdown-to-jsx/blob/4fa87d89ad87f97b2d9e56cb969d12f9a838f3ac/README.md?plain=1#L535-L537
Share on: