GHSA-gpfj-4j6g-c4w9
MODERATECVE-2021-37700A self Cross-Site Scripting vulnerability exists in the @github/paste-markdown library. If the clipboard data contains the string <table>, a div is dynamically created, and the clipboard content is copied into its innerHTML property without any sanitization, resulting in improper execution of JavaScript in the browser of the victim (the user who pasted the code). Users directed to copy text from a
- Affected
- < 0.3.4
- Fixed in
- 0.3.4
- Weakness
- CWE-79
- Published
- 2021-08-12
- Source
- github