CVE-2025-59717

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2025
Last modified:
08/10/2025

Description

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digitalocean:do-markdownit:*:*:*:*:*:node.js:*:* 1.16.1 (including)