Tag
marked
Safeguard articles tagged "marked" — guides, analysis, and best practices for software supply chain and application security.
3 articles
Vulnerability Analysis
CVE-2018-1000620: ReDoS in marked markdown parser
A ReDoS flaw in the marked Markdown parser (CVE-2018-1000620) let crafted input stall Node.js services. Here's the impact, fix, and how to catch it in your dependency tree.
Oct 14, 20258 min read
Vulnerability Analysis
CVE-2022-21681: Second ReDoS flaw in marked
CVE-2022-21681 is a ReDoS flaw in marked's inline tokenizer that lets crafted Markdown hang parsing. What's affected, severity, and how to remediate.
Oct 13, 20256 min read
Open Source
marked on npm: Security Review and Safe Usage
marked is a fast Markdown parser, but it does not sanitize output and older versions carried a ReDoS bug. Here is how to use marked npm without opening an XSS hole.
Feb 11, 20255 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.