Executive brief
Remarkable is a JavaScript markdown parser widely used in web applications to convert markdown text into HTML. The library failed to block data: URIs in markdown links, allowing attackers to craft markdown containing malicious JavaScript that would execute in the browser of anyone viewing the rendered content. This could lead to session hijacking, credential theft, or malware delivery.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in remarkable's link validation logic (CWE-79). The markdown parser did not filter or block data: URIs in link targets, allowing attackers to embed data: URLs containing JavaScript payloads (e.g., `[link](data:text/html,<script>alert('xss')</script>)`). When a user clicks such a link or the page is rendered, the JavaScript executes in the security context of the hosting domain. The vulnerability affects all versions prior to 1.7.0, and requires only that an attacker can inject markdown content into a document processed by the library. A fix was released in v1.7.0 with proper URI scheme validation.
Affected products
- remarkable remarkable <1.7.0
Timeline
- 2016-08-20: disclosed: Issue reported on GitHub
- 2018-11-09: advisory: GHSA advisory published
- 2017-01-01: patched: Fix released in v1.7.0