Executive brief
Markdown-Nice is a popular Markdown editor used for composing and formatting documents with custom themes. A cross-site scripting (XSS) vulnerability in version 1.8.22 allows attackers to inject malicious scripts through the Community Posting field, which are then executed in users' browsers. An attacker could exploit this to steal user credentials, redirect users to malicious sites, or deface content displayed to other users.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) issue in the Community Posting field of Markdown-Nice v1.8.22, stemming from insufficient input validation and sanitization (CWE-79). An attacker can inject arbitrary HTML/JavaScript payloads (e.g., `<img src=1 onerror=alert(1)>`) into the markdown preview functionality. The injected payload is executed client-side when the malicious content is viewed, affecting any user who accesses the compromised content. The attack vector is network-based, may require low privileges (depending on the deployment model), and benefits from user interaction to view the malicious content. Remediation via DOMPurify or similar HTML sanitization libraries is recommended.
Affected products
- mdnice markdown-nice through 1.8.22
Timeline
- 2022-08-21: disclosed: Vulnerability reported on GitHub issue #327
- 2022-09-09: disclosed: Published to NVD
- 2022-09-10: advisory: GHSA-462r-wxvm-jvxh advisory published