Affected versions of remarkable are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of data: URIs in links, and can therefore execute javascript.
[link](data:text/html,<script>alert('0')</script>)
Update to v1.7.0 or later
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T21:47:10Z",
"nvd_published_at": null,
"severity": "HIGH"
}