Junglewise Threat Intelligence

CVE-2021-39199: remark-html unsafe defaults allowing XSS

CVE-2021-39199 · Severity: low · CVSS 3.1 · Published 2021-09-07

Executive brief

remark-html is a popular JavaScript library that converts markdown to HTML. The library's documentation incorrectly claimed it was safe by default, but it actually allowed arbitrary HTML to pass through without sanitization, enabling cross-site scripting (XSS) attacks on any application using the default configuration.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw caused by unsafe default configuration in remark-html. The library did not sanitize HTML by default despite documentation claiming otherwise, allowing attackers to inject malicious scripts through markdown input. The attack requires no authentication and is network-accessible to any application processing untrusted markdown with this library. An attacker can execute arbitrary JavaScript in the context of affected applications. The issue was patched in versions 13.0.2 and 14.0.1, where sanitization is now enabled by default. Workaround for older versions involves explicitly passing `{sanitize: true}` option.

Affected products

  • remark remark-html all versions before 13.0.2; 14.0.0

Timeline

  • 2021-09-07: disclosed
  • 2021-09-07: patched: Patched in versions 13.0.2 and 14.0.1

References