ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in...
Low severity
Unreviewed
Published
Dec 15, 2024
to the GitHub Advisory Database
•
Updated Dec 16, 2024
Description
Published by the National Vulnerability Database
Dec 15, 2024
Published to the GitHub Advisory Database
Dec 15, 2024
Last updated
Dec 16, 2024
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.
References