Back

MEDIUM

Markdown-it 14.1.0 - Cross-site scripting (XSS)

Published Aug 21, 2025

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs.

This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Aug 21, 2025
Updated Dec 3, 2025
Reserved Jul 21, 2025
CISA Vulnrichment
Updated Aug 21, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 21, 2025
ENISA EUVD
Assigner Fluid Attacks
Published Aug 21, 2025
Updated Dec 3, 2025
Exploited since n/a
EUVD-2025-25465