Executive brief
markdown-it-toc is a popular Node.js library that generates table of contents automatically in markdown documents. A Cross-site Scripting (XSS) vulnerability in the library allows attackers to inject malicious scripts through unescaped header titles and TOC content, which execute in users' browsers when viewing generated documentation. This can lead to session hijacking, credential theft, or malware distribution.
Technical details
The vulnerability is a DOM-based XSS weakness (CWE-79) affecting all versions of markdown-it-toc up to and including 1.1.0. The title parameter of the generated table of contents and the contents of header elements are not properly HTML-escaped before insertion into the output. An attacker can craft malicious markdown input containing HTML tags and JavaScript that will be rendered unescaped in the final HTML output. The attack vector is network-based and requires user interaction (viewing the rendered markdown), but no authentication. An attacker can inject arbitrary JavaScript that executes in the context of the page viewing the generated documentation. No fix has been released for this library.
Affected products
- markdown-it-toc contributors markdown-it-toc <=1.1.0
Timeline
- 2020-11-24: disclosed: Vulnerability disclosed
- 2022-07-26: advisory: GHSA published