Skip to content
Critiq Docs

Search docs

Search documentation pages and rules

security.dependency

Upgrade Markdown rendering dependency

Markdown renderers should stay on patched versions before rendering untrusted content.

#Metadata

Rule ID
ts.security.unsafe-marked-version
Severity
high
Confidence
0.82
Languages
javascript, typescript
Presets
security, strict
Stability
experimental
Applies to
project
Tags
dependency, rules-catalog, security, xss

#Why it matters

Older Markdown renderer versions can expose unsafe HTML handling and parser edge cases.

#Remediation

Upgrade the package and keep untrusted Markdown rendering behind explicit sanitization.

#Repository path

The generated metadata points to critiq-rules/libs/rules/catalog/rules/typescript/ts.security.unsafe-marked-version.rule.yaml.