Note Mark
  • Support The Project
  • Security Disclosures - 2024-07

    Ability for XSS in rendered note content

    A stored cross-site scripting (XSS) vulnerability in Note Mark version v0.13.0 allows attackers to execute arbitrary web scripts in the markdown content that is activated when rendered.