« Back to list

Markdown-it Project

Markdown-it Project Markdown-it: vulnerabilities and CVEs

Markdown-it Project Markdown-it has 6 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-48988Medium (5.3)0.43%—Jun 17, 2026
markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from…
CVE-2026-2327Medium (5.5)0.68%—Feb 12, 2026
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long…
CVE-2025-7969Medium (6.9)0.24%—Aug 21, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files…
CVE-2015-10005High (7.5)0.95%—Dec 27, 2022
A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression…
CVE-2022-21670Medium (5.3)2.2%—Jan 10, 2022
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a…
CVE-2015-3295Medium (5.3)1.3%—Jun 7, 2017
markdown-it before 4.1.0 does not block data: URLs.