Junglewise Threat Intelligence

markdown-it-toc-and-anchor denial of service

Severity: low · CVSS 3.1 · Published 2020-09-01

Vendors: npm.

Executive brief

markdown-it-toc-and-anchor is a Node.js library plugin that adds table of contents and anchor links to markdown documents. A vulnerability in how the plugin parses markdown input causes it to enter an infinite loop when encountering specially crafted text, allowing an attacker to freeze or crash any application using the library with minimal network effort.

Technical details

The vulnerability is a Denial of Service condition caused by an infinite loop triggered during markdown parsing. When processing markdown containing the pattern **text**+\n@[toc], the plugin's parsing logic enters a repeating cycle that consumes CPU indefinitely. The attack requires no authentication or user interaction and is reachable over the network to any application accepting user-supplied markdown input. An attacker can exploit this by submitting crafted markdown to cause the target application to hang or crash. As of the advisory date, no patch was available; version 4.2.0 and later address this issue.

Affected products

  • markdown-it-toc-and-anchor markdown-it-toc-and-anchor <4.2.0

Timeline

  • 2019-01-03: disclosed
  • 2020-09-01: advisory
  • 2019-01-03: patched: Fix released in version 4.2.0

References