remarkable
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting remarkablepage 1 of 1
- CVE-2014-10065MEDIUMCVSS 6.1✓ Fixed in 1.4.12018-05-31
Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content.
- CVE-2017-16006MEDIUMCVSS 6.1✓ Fixed in 1.7.02018-06-04
Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.
- CVE-2019-12041HIGHCVSS 7.5EG 7.5✓ Fixed in 1.7.22019-05-13
lib/common/html_re.js in remarkable 1.7.1 allows Regular Expression Denial of Service (ReDoS) via a CDATA section.
- CVE-2019-12043MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.7.22019-05-13
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Check whether remarkable is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for remarkable CVEs against the assets you own.
Start Free Scan →