QID 983080
QID 983080: Nodejs (npm) Security Update for remarkable (GHSA-f9vc-q3hh-qhfv)
Versions 1.4.0 and earlier of `remarkable` are affected by a cross-site scripting vulnerability. This occurs because vulnerable versions of `remarkable` did not properly whitelist link protocols, and consequently allowed `javascript:` to be used.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-f9vc-q3hh-qhfv for updates pertaining to this vulnerability.
Vendor References
- GHSA-f9vc-q3hh-qhfv -
github.com/advisories/GHSA-f9vc-q3hh-qhfv
CVEs related to QID 983080
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f9vc-q3hh-qhfv | remarkable |
|