Markdown-it 14.1.0 - Cross-site scripting (XSS)
Published Aug 21, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.24%
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs.
This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability.
Affected products
-
- Version 14.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Markdown-IT | Markdown-IT | unaffected |
|
- 14.1.0
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Fix deferred
OpenShift Serverless
openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8
Fix deferred
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Fix deferred
Red Hat Developer Hub
rhdh/rhdh-rhel9-operator
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces-tech-preview/idea-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/code-rhel8
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel8
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Fix deferred | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8 | Fix deferred | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Fix deferred | n/a |
| Red Hat Developer Hub | rhdh/rhdh-rhel9-operator | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces-tech-preview/idea-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel8 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-7969 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2390127 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25465 Advisory
- https://fluidattacks.com/advisories/fito exploitthird-party-advisoryThird Party Advisory
- https://github.com/markdown-it/markdown-it product
- https://github.com/markdown-it/markdown-it/issues/1122 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2025-7969
- https://www.cve.org/CVERecord?id=CVE-2025-7969
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-7969 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2390127 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-25465 | Advisory | |
| https://fluidattacks.com/advisories/fito | exploitthird-party-advisoryThird Party Advisory | |
| https://github.com/markdown-it/markdown-it | product | |
| https://github.com/markdown-it/markdown-it/issues/1122 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-7969 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-7969 |
Change history (0)
No recorded changes yet.