MarkTwo Cross-Site Scripting Vulnerability in Markdown Editor

Vulnerability

A Cross-Site Scripting (XSS) vulnerability has been identified in the MarkTwo Markdown Editor, specifically in commit e3a1d3f90cce4ea9c26efcbbf3a1cbfb9dcdb298, which is the latest version as of May 2025. This vulnerability allows remote attackers to execute arbitrary code by injecting a crafted script into the editor interface. The issue arises because the application fails to properly sanitize user-generated Markdown before rendering it. Exploitation of this vulnerability could result in session hijacking, theft of credentials, or execution of arbitrary client-side code in the context of the user's browser.

Impact

Exploitation of this vulnerability could lead to session hijacking, credential theft, or execution of arbitrary client-side code in the context of the victim's browser.

Reproduction

To reproduce this vulnerability, inject a script payload into the Markdown editor. The absence of proper input sanitization will allow the script to be executed, demonstrating the XSS vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.5
exploitability
7.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.