QID 983164
QID 983164: Nodejs (npm) Security Update for remarkable (GHSA-mrmf-qwxg-7c3h)
Affected versions of `remarkable` are vulnerable to cross-site scripting. Vulnerable versions of the package allow the use of `data:` URIs in links, and can therefore execute javascript.
## Proof of Concept
```
[link](data:text/html,<script>alert('0')</script>)
```
## Recommendation
Update to v1.7.0 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mrmf-qwxg-7c3h for updates pertaining to this vulnerability.
Vendor References
- GHSA-mrmf-qwxg-7c3h -
github.com/advisories/GHSA-mrmf-qwxg-7c3h
CVEs related to QID 983164
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mrmf-qwxg-7c3h | remarkable |
|