CVE-2025-7969 MEDIUM

CVE-2025-7969: Markdown-it 14.1.0 - Cross-site scripting (XSS)

Vendor Markdown-It
Product markdown-it
Weakness CWE-79 · XSS
Published August 21, 2025
Last update December 3, 2025

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in markdown-it allows Cross-Site Scripting (XSS). This vulnerability is associated with program files lib/renderer.mjs. This issue affects markdown-it: 14.1.0. NOTE: the Supplier does not consider this issue to be a vulnerability.

Key dates

02Disclosure timeline

August 21, 2025 CVE published
December 3, 2025 Record updated