Markdown Parser Vulnerability in Remarkable by Jonschlinkert
CVE-2017-16006

6.1MEDIUM

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
4 June 2018

What is CVE-2017-16006?

Remarkable, a popular markdown parser, has a security vulnerability in versions 1.6.2 and earlier. This flaw allows the inclusion of data: URIs in markdown links, which can lead to unintended JavaScript execution. Attackers could exploit this vulnerability to execute malicious scripts within the context of the application, raising significant security concerns for users utilizing this parser. Users are advised to review the latest updates and consider applying necessary patches to mitigate risks associated with this vulnerability.

Affected Version(s)

remarkable node module <=1.6.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.