An open index of dependabot pull requests across open source projects.

marked

Ecosystem:
npm
Package URL:
pkg:npm/marked
Total PRs:
4,654 Dependabot PRs
Latest PR:
about 8 hours ago
Unique Repositories:
1,579 repositories
Unique Repos (30 days):
106 repositories
Security Advisories
Multiple Content Injection Vulnerabilities in marked
GHSA-9cw2-jqp5-7x39 CVE-2014-3743 MODERATE published almost 6 years ago • updated 10 days ago
Versions 0.3.0 and earlier of `marked` are affected by two cross-site scripting vulnerabilities, even when `sanitize: true` is set. The attack vec...
Inefficient Regular Expression Complexity in marked
GHSA-rrrm-qjm4-v8hf CVE-2022-21680 HIGH published over 4 years ago • updated 11 days ago
### Impact _What kind of vulnerability is it?_ Denial of service. The regular expression `block.def` may cause catastrophic backtracking against...
Regular Expression Denial of Service in marked
GHSA-ch52-vgq2-943f LOW published almost 6 years ago • updated 10 days ago
Affected versions of `marked` are vulnerable to Regular Expression Denial of Service (ReDoS). The `_label` subrule may significantly degrade parsin...
Marked ReDoS due to email addresses being evaluated in quadratic time
GHSA-xf5p-87ch-gxw2 MODERATE published about 7 years ago • updated about 2 months ago
Versions of `marked` from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic ...
Marked Vulnerable to OOM Denial of Service via Infinite Recursion in marked Tokenizer
GHSA-6v9c-7cg6-27q7 CVE-2026-41680 HIGH published about 2 months ago • updated 6 days ago
### Summary A critical Denial of Service (DoS) vulnerability exists in `marked@18.0.0`. By providing a specific 3-byte input sequence a tab, a vert...
Recent PRs
Package Details
Name: marked
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/marked
JSON API: View JSON
Security Advisories

13

Active advisories
HIGH 5
MODERATE 7
LOW 1
View All npm Advisories
Package Information
Description:

A markdown parser built for speed

Repository: https://github.com/markedjs/marked
Homepage: https://marked.js.org
Latest Release: 15.0.12
about 1 year ago
Dependent Repos: 468,889
Dependent Packages: 12,165
Downloads: 53,233,314
Ranking: Top 0.0534% by dependent repos Top 0.0421% by downloads Top 0.0083% by dependent pkgs
PR Status
Open 2,190 (47.1%)
Merged 459 (9.9%)
Closed 1,770 (38.0%)
PR Types
Major 2,275 (48.9%)
Minor 760 (16.3%)
Patch 1,376 (29.6%)
Removal 6 (0.1%)