{"id":"GHSA-cfjh-p3g4-3q2f","summary":"VBScript Content Injection in marked","details":"Versions 0.3.2 and earlier of `marked` are affected by a cross-site scripting vulnerability even when `sanitize:true` is set. \n\n## Proof of Concept ( IE10 Compatibility Mode Only )\n\n`[xss link](vbscript:alert(1&#41;)`\n\nwill get a link\n\n`\u003ca href=\"vbscript:alert(1)\"\u003exss link\u003c/a\u003e`\n\n\n## Recommendation\n\nUpdate to version 0.3.3 or later.","aliases":["CVE-2015-1370"],"modified":"2023-11-01T04:45:57.846132Z","published":"2017-10-24T18:33:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:31:22Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1370"},{"type":"WEB","url":"https://github.com/chjj/marked/issues/492"},{"type":"WEB","url":"https://github.com/markedjs/marked/issues/492"},{"type":"WEB","url":"https://github.com/evilpacket/marked/commit/3c191144939107c45a7fa11ab6cb88be6694a1ba"},{"type":"WEB","url":"https://github.com/markedjs/marked/commit/fc372d1c6293267722e33f2719d57cebd67b3da1"},{"type":"PACKAGE","url":"https://github.com/markedjs/marked"},{"type":"WEB","url":"https://www.npmjs.com/advisories/24"},{"type":"WEB","url":"https://www.npmjs.com/advisories/24/versions"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/01/23/2"}],"affected":[{"package":{"name":"marked","ecosystem":"npm","purl":"pkg:npm/marked"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-cfjh-p3g4-3q2f/GHSA-cfjh-p3g4-3q2f.json"}}],"schema_version":"1.9.0"}