Inefficient Algorithmic Complexity Affecting markdown-it package, versions <14.2.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-MARKDOWNIT-17353909
  • published17 Jun 2026
  • disclosed15 Jun 2026
  • creditByunSuyoung

Introduced: 15 Jun 2026

NewCVE-2026-48988  (opens in a new tab)
CWE-407  (opens in a new tab)

How to fix?

Upgrade markdown-it to version 14.2.0 or higher.

Overview

markdown-it is a modern pluggable markdown parser.

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity through the replaceAt() function in the smartquotes rule when processing markdown input with a large number of consecutive quotation marks and the typographer option enabled. An attacker can cause excessive CPU consumption and disrupt service availability by submitting specially crafted markdown content containing many quote characters.

CVSS Base Scores

version 4.0
version 3.1