marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
| Software | From | Fixed in |
|---|---|---|
| marked_project / marked | - | 0.3.6.x |
marked
|
- | 0.3.7 |