CVE-2025-59717: @digitalocean/do-markdownit has Type Confusion vulnerability
(updated )
Supplying crafted input can bypass intended allow-lists (e.g., class/environment constraints) due to substring checks, which may enable rendering of unintended classes or environments and lead to policy bypass in downstream consumers.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-59717 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →