RUSTSEC-2021-0063
Dashboard / Vulnerabilities / RUSTSEC-2021-0063
RUSTSEC-2021-0063
Summary: XSS in `comrak`
Details: [comrak](https://github.com/kivikakk/comrak) operates by default in a "safe" mode of operation where unsafe content, such as arbitrary raw HTML or URLs with non-standard schemes, are not permitted in the output. This is per the reference GFM implementation, [cmark-gfm](https://github.com/github/cmark). Ampersands were not being correctly escaped in link targets, making it possible to fashion unsafe URLs using schemes like `data:` or `javascript:` by entering them as HTML entities, e.g. `data:`. The intended behaviour, demonstrated upstream, is that these should be escaped and therefore harmless, but this behaviour was broken in comrak.
References: https://crates.io/crates/comrak, https://rustsec.org/advisories/RUSTSEC-2021-0063.html, https://github.com/kivikakk/comrak/releases/tag/0.10.1
Affected packages
Package
Name: comrak
Purl: pkg:cargo/comrak
Affected ranges
Type: SEMVER
Events:
