Repository navigation
Security Vulnerability #1477
Description
Activity
Can you mail Snyk first regarding the vulnerability. And we will take action once there is a confirmation from them.
Also, feel free to DM us in discord if it helps.
Thanks.Reacted by Joe Pea, EgiX and Koy Zhuang- added a commit that references this issue
on Feb 5, 2021 - added a commit that references this issue
on Feb 5, 2021 - added a commit that references this issue
on Feb 14, 2021 - added a commit that references this issue
on Feb 18, 2021 Hi @anikethsaha,
I can still reproduce the vulnerability with docsify version 4.12.0. By using more than two forward slashes (i.e.
///) is still possible to load an external URL and its HTML content is not correctly sanitized, both in the sidebar and main page:@EgidioRomano Can you use this for testing?
<link rel="stylesheet" href="//cdn.jsdelivr.net/gh/sy-records/docsify-nightly/lib/themes/vue.css" /> <script src="//cdn.jsdelivr.net/gh/sy-records/docsify-nightly/lib/docsify.min.js"></script>
or use https://docsify-preview.now.sh/ testing
Hi @sy-records,
My Proof of Concept doesn't work on https://docsify-preview.now.sh.
Is it running a different version than the one at https://docsify.js.org ?Yes,
docsify-preview.now.shis the develop branch preview,docsify.js.orgis the master branch.
You can use my nightly version https://github.com/sy-records/docsify-nightlyIf the fix is with the dev branch, is it possible to push it to master and publish a new release @sy-records?
If the fix is with the dev branch, is it possible to push it to master and publish a new release @sy-records?
cc @docsifyjs/reviewers
@sy-records I think we can release a patch on this recently, maybe next week.
I will review some new PRs at this weekend.@sy-records Yes, we should push a patch release to address the security issue ASAP.
Any update on this? thanks
- Reacted by Sam Sanoop
This vulnerability seems to still exist. I'm able to reproduced it against 4.13.
I cannot produce it against https://docsify-preview.vercel.app/#/ (which just gives a
404 - Not foundinstead).So I think it's fixed in development? Can a new release be done? Thanks.
@volosied I think it should have been released, can you send me the reproduction script?
This issue was discovered by another individual. He provided the following page to test with. See here:
yeah, I know, fixed via #2093
Reacted by Volodymyr Siedlecki and Henning Noeth@sy-records thanks for your work! When can we expect a new release?
Hi @henningn , I think we gonna have a patch of this asap.
Hi @sy-records , could u plz raise the new release based on the last release commit as a hotfix instead of current dev branch? since we have marked changes need more clarify... if u are not free for this recently, u could ask me to do so as well.
see #2101
Reacted by Koy Zhuang and Henning NoethReacted by Henning Noeth

Hi!
On December 23, 2020 I've tried to reach out to you in order to report details about a security vulnerability in Docsify.js, but I still haven't received any response to my email. Is there an appropriate channel where I should report the security issue?