CVE-2025-7969: Markdown-it 14.1.0 - Cross-site scripting (XSS)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs.
This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7969?
CVE-2025-7969 is classified as a medium severity vulnerability due to the potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-7969?
To address CVE-2025-7969, you should upgrade to the latest version of markdown-it that contains the patch for this vulnerability.
What software versions are affected by CVE-2025-7969?
CVE-2025-7969 affects markdown-it version 14.1.0 and potentially earlier versions.
What type of vulnerability is CVE-2025-7969?
CVE-2025-7969 is an Improper Neutralization of Input During Web Page Generation vulnerability, commonly known as a Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-7969 lead to data exposure?
Yes, CVE-2025-7969 can lead to unauthorized access and data exposure if exploited, allowing attackers to execute scripts in the context of a user’s browser.