4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether markdown-it is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-48988
markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations
MEDIUM 5.3
CVE-2026-2327
markdown-it is has a Regular Expression Denial of Service (ReDoS)
MEDIUM 5.3
CVE-2022-21670
Uncontrolled Resource Consumption in markdown-it
HIGH 7.5
CVE-2015-10005
markdown-it vulnerable to Inefficient Regular Expression Complexity
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes