QID 981789
QID 981789: Nodejs (npm) Security Update for remarkable (GHSA-36m4-6v6m-4vpr)
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-36m4-6v6m-4vpr for updates pertaining to this vulnerability.
Vendor References
- GHSA-36m4-6v6m-4vpr -
github.com/advisories/GHSA-36m4-6v6m-4vpr
CVEs related to QID 981789
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-36m4-6v6m-4vpr | remarkable |
|