Inefficient Algorithmic Complexity Affecting markdown-it package, versions <14.3.1>=15.0.0 <15.0.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-MARKDOWNIT-20335431
  • published30 Sept 2026
  • disclosed29 Sept 2026
  • creditIain, Alicia Sykes

Introduced: 29 Sep 2026

New CVE NOT AVAILABLE CWE-407  (opens in a new tab)

How to fix?

Upgrade markdown-it to version 14.3.1, 15.0.1 or higher.

Overview

markdown-it is a modern pluggable markdown parser.

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the linkify rule (src/rules_core/linkify.ts) via input containing multiple fuzzy links. The arrayReplaceAt utility was called repeatedly inside the token-processing loop, causing each replacement to copy the entire token array, resulting in O(n²) time complexity as the number of links grows. An attacker can trigger excessive CPU consumption by supplying input with a large number of linkified URLs.

CVSS Base Scores

version 4.0
version 3.1