markdown-to-jsx@7.0.1 vulnerabilities

Convert markdown to JSX with ease for React and React-like projects. Super lightweight and highly configurable.

Direct Vulnerabilities

Known vulnerabilities in the markdown-to-jsx package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Regular Expression Denial of Service (ReDoS)

markdown-to-jsx is a lightweight, customizable React markdown component.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). Catastrophic backtracking in the BREAK_THEMATIC_R regex causes parsing to hang on non-matching input with repeating asterisks

How to fix Regular Expression Denial of Service (ReDoS)?

Upgrade markdown-to-jsx to version 7.2.0 or higher.

<7.2.0