1. SvelteMarkdown 1.3.0 XSS Vulnerability: Markdown Link Injection Bypasses Pre-Parsing Sanitization
A critical security flaw in the `@humanspeak/svelte-markdown` library version 1.3.0 allows attackers to bypass standard HTML sanitization, creating a direct path for cross-site scripting (XSS) attacks. The vulnerability, discovered by researcher @ShinonomeNoAlice, exploits the library's fundamental processing order: sa...