Executive brief
Marp Core is a Markdown-to-HTML presentation framework used to create and render slide decks. A cross-site scripting (XSS) vulnerability in its built-in HTML sanitizer allows attackers to inject malicious scripts when HTML content contains specific comment patterns, potentially enabling session hijacking, credential theft, or malware distribution to viewers of affected presentations.
Technical details
Marp Core versions 3.0.2 through 3.9.0 and 4.0.0 contain an XSS vulnerability (CWE-79) in the HTML sanitizer component. The sanitizer uses an allowlist-based approach that is enabled by default, but fails to properly neutralize HTML when insufficient HTML comments are present in the input. An attacker can craft malicious Markdown or HTML content with specially crafted HTML comments that bypass the sanitizer, allowing arbitrary JavaScript execution in the context of the rendered presentation. The vulnerability requires local access and user interaction (opening a malicious presentation file). The issue has been patched in versions 3.9.1 and 4.0.1; users can also mitigate by disabling HTML parsing via the html: false configuration option.
Affected products
- Marp Team Marp Core 3.0.2 to 3.9.0, 4.0.0
Timeline
- 2024-12-26: disclosed
- 2024-12-26: patched: v3.9.1 and v4.0.1