Showing 1 vulnerability on this page for paste-markdown

Signals CISA KEV Ransomware Nuclei
GitHub vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Clipboard-based DOM-XSS

@github/paste-markdown is an npm package for pasting markdown objects. A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown before version 0.3.4. If the clipboard data contains the string `<table>`, a **div** is dynamically created, and the clipboard content is copied into its **innerHTML** property without any sanitization, resulting in improper execution of JavaScript in the browser of the victim (the user who pasted the code). Users directed to copy text from a malic

CWE-79Aug 12, 2021
CVSS6.5v3.1EPSS1.66%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX