Versions 0.3.7 and earlier of marked When mangling is disabled via option mangle don't escape target href. This allow attacker to inject arbitrary html-event into resulting a tag.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2019-06-05T20:56:48Z",
"nvd_published_at": null,
"severity": "MODERATE"
}