Advisories for Npm/Buttle package

2020

Cross-Site Scripting in buttle

All versions of buttle are vulnerable to Cross-Site Scripting. Due to misconfiguration of its rendering engine, buttle does not sanitize the HTML output allowing attackers to run arbitrary JavaScript when processing malicious markdown files. Recommendation No fix is currently available. Consider using an alternative module until a fix is made available.

2019

Cross-site Scripting

XSS in buttle causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.

2018