Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade markdown-it to version 14.3.1, 15.0.1 or higher.
markdown-it is a modern pluggable markdown parser.
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the linkify rule (src/rules_core/linkify.ts) via input containing multiple fuzzy links. The arrayReplaceAt utility was called repeatedly inside the token-processing loop, causing each replacement to copy the entire token array, resulting in O(n²) time complexity as the number of links grows. An attacker can trigger excessive CPU consumption by supplying input with a large number of linkified URLs.