An issue was discovered in the comrak crate before 0.9.1 for Rust. Cross site scripting (XSS) can occur because the protection mechanism for data: and javascript: URIs is case-sensitive, allowing (for example) Data: to be used in an attack.
{ "nvd_published_at": null, "github_reviewed_at": "2021-08-19T17:34:25Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }