Skip to content

fix(security): remediate markdown-it vulnerability - #244

Closed
GioDavid wants to merge 2 commits into
mainfrom
security/markdown-it-14.3.2
Closed

GioDavid wants to merge 2 commits into
mainfrom
security/markdown-it-14.3.2

Conversation

@GioDavid

@GioDavid GioDavid commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

Resolves the moderate markdown-it denial-of-service advisory GHSA-253c-mchw-3w2r (CWE-400, CWE-407). Versions below 14.3.1, including the installed 14.2.0, have two quadratic paths when linkify: true is enabled. The patched 14.x release is 14.3.1; this change resolves 14.3.2, the latest 14.x release, which also backports the 15.0.2 smartquotes fix. markdown-it 15.0.2 is a breaking major (linkify-it v6, removed internal subpath exports) and was not used.

markdown-it is not part of the React Native runtime. It is a documentation dependency of TypeDoc. TypeDoc's default markdownItOptions set linkify: true, so the vulnerable option is enabled when yarn docs runs. typographer stays off unless configured. Documentation input is repository source, so this is not an exposed runtime parser.

Dependency path

react-native-spotlight-tour (package workspace)
  → typedoc@0.28.19
    → markdown-it@14.2.0 (requested ^14.1.1)

Both yarn why entries are the same typedoc dependency (workspace instance and its virtual locator). One installed version. Immediate parent and high-level parent are both typedoc.

Package-only investigation

typedoc@0.28.19 already requests markdown-it@^14.1.1, which allows 14.3.2.

yarn up -R markdown-it

That resolves markdown-it@14.3.2. markdown-it@14.3.2 requires linkify-it@^5.0.2, so the lockfile also moves linkify-it from 5.0.1 to 5.0.2 and updates the entities descriptor from ^4.4.0 to ^4.5.0 (still resolved at 4.5.0). Only yarn.lock changes.

Parent investigation

typedoc@0.28.20 is the latest 0.28 patch. Its changelog has no breaking changes. It raises markdown-it to ^14.3.0.

Tested with:

yarn workspace react-native-spotlight-tour up typedoc@0.28.20

Result: markdown-it resolved to 14.3.2. The update also pinned typedoc to 0.28.20 and added yaml@2.9.1 for typedoc's yaml@^2.9.0 range. ^14.3.0 still includes 14.3.0, which is inside the GHSA-253c-mchw-3w2r affected range, so the parent release does not itself require a fixed version. 0.28.20 was published on 2026-07-05, before this advisory.

Final remediation

Lockfile-only update to markdown-it@14.3.2.

The parent update reaches the same markdown-it version only by floating to the newest match, and it changes TypeDoc and yaml without an additional security fix for this advisory. The existing range already permits 14.3.2, so the smaller lockfile change is the selected remediation.

Validation

  • yarn install --immutable
  • yarn why markdown-it → 14.3.2 via typedoc@0.28.19 (^14.1.1)
  • yarn test --force → 22 tests passed
  • yarn lint → passed
  • yarn docs → TypeDoc markdown generation completed
  • yarn npm audit → no markdown-it finding
  • Changed files: yarn.lock only

Scope

This PR only remediates markdown-it. The linkify-it 5.0.2 resolution is required by markdown-it@14.3.2 and is not a separate vulnerability fix. The same lockfile movement is also on open PR #243, which used a markdown-it bump to remediate linkify-it. These two PRs should not both be merged as-is.

Made with Cursor

TypeDoc renders documentation with linkify enabled, and markdown-it 14.2.0 is affected by GHSA-253c-mchw-3w2r. The existing typedoc range already allows the patched 14.3.2 release.

Co-authored-by: Cursor <cursoragent@cursor.com>
@GioDavid
GioDavid requested a review from suany0805 October 2, 2026 15:21
@GioDavid

GioDavid commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator Author

solved using dependabots

@GioDavid GioDavid closed this Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant