QID 981154
QID 981154: Nodejs (npm) Security Update for remark-html (GHSA-9q5w-79cv-947m)
Security update has been released for remark-html to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
The documentation of `remark-html` has mentioned that it was safe by default. In practise the default was never safe and had to be opted into. This means arbitrary HTML can be passed through leading to potential XSS attacks.
Solution
The problem has been patched in 13.0.2 and 14.0.1: `remark-html` is now safe by default, and the implementation matches the documentation.Workaround:
On older affected versions, pass `sanitize: true`, like so:
```diff
- .use(remarkHtml)
+ .use(remarkHtml, {sanitize: true})
```
On older affected versions, pass `sanitize: true`, like so:
```diff
- .use(remarkHtml)
+ .use(remarkHtml, {sanitize: true})
```
Vendor References
- GHSA-9q5w-79cv-947m -
github.com/advisories/GHSA-9q5w-79cv-947m
CVEs related to QID 981154
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9q5w-79cv-947m | remark-html |
|