Executive brief
Remarkable is a popular Markdown parser library used to convert user-written Markdown into HTML for display in web applications. Versions 1.4.0 and earlier fail to properly block the "javascript:" protocol in links, allowing attackers to inject malicious JavaScript code that executes when users click crafted links. This could lead to account compromise, session hijacking, or theft of sensitive data from affected users.
Technical details
The vulnerability is a cross-site scripting (XSS) / content injection flaw caused by improper URL protocol whitelisting in the link rendering component. Versions 1.4.0 and earlier do not properly escape or validate the protocol portion of URLs in Markdown links, allowing the dangerous "javascript:" protocol to pass through to the rendered HTML. An attacker can craft a Markdown snippet like `[link](<javascript:alert(1)>)` which renders as an exploitable HTML anchor tag with `href="javascript:alert(1)"`. No authentication or special preconditions are required—any user-supplied Markdown processed by the library is affected. The fix was released in version 1.4.1.
Affected products
- jonschlinkert remarkable 1.4.0 and earlier
Timeline
- 2014-11-06: disclosed: Issue reported on GitHub
- 2014: patched: Fix released in version 1.4.1
- 2020-08-31: advisory: GHSA-f9vc-q3hh-qhfv published