Affected versions of gitbook do not properly sanitize user input outside of backticks, which may result in cross-site scripting in the online reader.
Update to version 3.2.2 or later.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2020-08-31T18:12:55Z",
"nvd_published_at": null,
"severity": "MODERATE"
}