Skip to content

Conversation

@pensarapp
Copy link

@pensarapp pensarapp bot commented Jul 6, 2025

Secured with Pensar

Upgrading marked from 0.3.5 to 4.0.10

Fixes Summary

File Fix Explanation
 /package-lock.json 
Upgrading to marked version 4.0.10 resolves all listed vulnerabilities. Earlier versions (0.3.6 and 0.3.9) addressed some issues such as XSS and basic ReDoS concerns, but marked versions prior to 4.0.10 remain vulnerable to more advanced Regular Expression Denial of Service attacks due to inefficient regex implementations. Version 4.0.10 provides the necessary fixes for proper sanitization of HTML entities and optimizes regular expression handling to prevent catastrophic backtracking, making it the minimum version that fully mitigates the security risks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant