-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from EpicEditor's insecure default marked.js configuration where sanitization is disabled (sanitize: false). This configuration is explicitly shown in third-party analysis and matches the XSS vector description. While the exact function name/path isn't specified in available resources, the root cause is clearly the marked.js options initialization logic in EpicEditor's codebase that fails to enable sanitization by default.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| epiceditor | npm | <= 0.2.3 |
KEV Misses 88% of Exploited CVEs- Get the report