dev-rfc
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyassets/marked.min.js
LOWAnomalyLOW
assets/marked.min.js
The visible code is a legitimate Markdown lexer/parser/HTML renderer and shows no evidence of malicious supply-chain behavior. The principal security concern is application-level XSS risk: raw HTML is intentionally passed through, and URL encoding alone may not reject dangerous schemes. Untrusted Markdown should be sanitized and link/image protocols should be allowlisted before browser rendering.
Confidence: 98%Severity: 58%
Audit Metadata