Denial of Service in markdown-it-toc-and-anchor
High severity
GitHub Reviewed
Published
Sep 1, 2020
to the GitHub Advisory Database
•
Updated Dec 7, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 1, 2020
Last updated
Dec 7, 2023
All versions of
markdown-it-toc-and-anchor
are vulnerable to Denial of Service. Parsing markdown containing**text**+\n@[toc]
causes the application to enter and infinite loop.Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
References