Executive brief
Marked is a popular JavaScript library used to convert Markdown text into HTML. Versions 0.3.6 and earlier fail to properly sanitize data URIs, allowing an attacker to inject malicious scripts that execute in a user's browser when the Markdown is rendered. This could lead to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw (CWE-79) in the data: URI parser component of Marked. Versions 0.3.6 and earlier fail to properly sanitize or neutralize user-controlled input within data URIs before rendering the output as HTML. An attacker can craft a Markdown document containing a malicious data URI in a link or image element that, when processed by Marked, executes arbitrary JavaScript in the context of the page. The attack requires user interaction (opening or viewing the crafted Markdown), but has network reach since Markdown can be served remotely. The fix is available in version 0.3.7 and later.
Affected products
- markedjs Marked <0.3.7
Timeline
- 2018-01-04: disclosed
- 2018-01-04: patched: Fixed in Marked 0.3.7