redcarpet
A fast, safe and extensible Markdown to (X)HTML parser
Activity
- Latest release
- 1y ago
- Total releases
- 75
- Cadence
- ~6 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Mar 28, 2011
| Version | Released | |
|---|---|---|
3.6.1
patch
| ||
3.6.0
minor
| ||
3.5.1
patch
| ||
3.5.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.4.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.4
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.3
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.1
patch
2 CVEs
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-5147
GHSA-7322-9mx6-5j2m
Aug 15, 2018
redcarpet Buffer Overflow vulnerability
High
Stack-based buffer overflow in the Affected versions
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
3.3.0
minor
2 CVEs
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2015-5147
GHSA-7322-9mx6-5j2m
Aug 15, 2018
redcarpet Buffer Overflow vulnerability
High
Stack-based buffer overflow in the Affected versions
3.3.0
3.3.1
Fixed in
3.3.2
References
Updated Dec 05, 2024 · Source: OSV.dev | ||
3.2.3
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.2.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.2.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.1.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.1.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.0b5
pre
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.0b4
pre
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.0b3
pre
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.0b
pre
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.17.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.17.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.17.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.16.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.15.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.15.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.14.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.14.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.14.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.13.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.13.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.12.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.12.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.11.4
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.11.3
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.11.2
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
1.11.1
patch
1 CVE
CVE-2020-26298
GHSA-q3wr-qw3g-3p4h
Jan 11, 2021
Injection/XSS in Redcarpet
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
None
High
None
Redcarpet is a Ruby library for Markdown processing. In Redcarpet before version 3.5.1, there is an injection vulnerability which can enable a cross-site scripting attack. In affected versions no HTML escaping was being performed when processing quotes. This applies even when the Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.10.0
1.10.1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.12.0
+ 60 more Show less
1.12.1
1.12.2
1.13.0
1.13.1
1.13.2
1.14.0
1.14.1
1.14.2
1.15.0
1.15.1
1.15.2
1.16.0
1.17.0
1.17.1
1.17.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.7.0
1.7.1
1.8.0
1.8.1
1.8.2
1.9.0
2.0.0
2.0.0b
2.0.0b3
2.0.0b4
2.0.0b5
2.0.1
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.3.0
3.0.0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
3.2.2
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.5.0
Fixed in
3.5.1
References
Updated Jul 08, 2026 · Source: OSV.dev |