Junglewise Threat Intelligence

CVE-2018-19057: SimpleMDE Markdown Editor XSS in image and link handling

CVE-2018-19057 · Severity: low · CVSS 3 · Published 2018-11-21

Vendors: npm.

Executive brief

SimpleMDE is a popular JavaScript markdown editor used in web applications to allow users to create formatted content. The vulnerability allows attackers to inject malicious JavaScript code through specially crafted image tags or markdown link syntax, which executes in the browsers of users viewing the rendered content. This could enable session hijacking, credential theft, or account takeover for affected users.

Technical details

SimpleMDE 1.11.2 and earlier versions contain a cross-site scripting (XSS) vulnerability due to improper sanitization of user input when constructing IMG and A HTML elements. An attacker can bypass input validation by injecting an onerror attribute in a crafted IMG tag (e.g., `<img onerror=eval(id)>`) or by using malicious JavaScript URLs in markdown link syntax with specific character combinations like `[text](javascript:alert())`. The vulnerability requires user interaction—a victim must either enter the malicious payload into the editor or view content containing it. No patch information is explicitly mentioned in the advisory, but the issue was reported to the upstream SimpleMDE project.

Affected products

  • Spark Suite SimpleMDE 1.11.2 and earlier

Timeline

  • 2018-11-07: disclosed: Issue opened on GitHub
  • 2018-11-21: advisory: GHSA-wg85-p6j7-gp3w published

References