← Back to CVE List

CVE-2024-21535

Published: 2024-10-15T05:15Z
Last Modified: 2024-10-17T20:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt