Executive brief
editor.md is an open-source Markdown editor used to provide rich text editing capabilities in web applications. A security flaw allows attackers to embed malicious scripts within Markdown content, which could lead to unauthorized actions or data theft when other users view the edited text. Because no official patch is available, organizations using this component may be at risk of account hijacking or session theft.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in editor.md version 1.5.0. The issue stems from improper neutralization of user-controllable input within the Markdown rendering engine, specifically when processing '<EMBED>' tags. An attacker can bypass sanitization by using a 'data:image/svg+xml;base64' source containing a malicious script payload. When a victim views the rendered Markdown, the injected script executes in the context of their browser session. As of the latest advisory update, no official patch has been released, and users are advised to seek alternative libraries.
Affected products
- pandao editor.md 1.5.0
Timeline
- 2019-03-07: disclosed: Issue reported on GitHub repository
- 2019-03-12: advisory: NVD published CVE-2019-9737
- 2019-03-14: advisory: GitHub Advisory GHSA-2j5v-fc74-j9q2 published