GHSA-j82m-pc2v-2484
CRITICALCVE-2025-24981An unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the javascript: protocol scheme in the URL.
- Affected
- <= 0.13.2
- Fixed in
- 0.13.3
- Weakness
- CWE-79
- Published
- 2025-02-06
- Source
- github