Content Security Policy (CSP) can limit the impact of cross-site scripting, clickjacking, mixed content, and untrusted resource loading, but it is a defense-in-depth control rather than a replacement for input validation and output sanitization. Effective policies use per-response cryptographically random nonces or script hashes, narrowly define resource sources, set object-src, base-uri, form-action, and frame-ancestors explicitly, and can use Trusted Types to restrict dangerous DOM injection sinks such as innerHTML, document.write(), and eval().
Misconfigured policies can provide a false sense of security: unsafe-inline, unsafe-eval, data:, broad schemes, wildcards, and permissive third-party script allowlists can enable XSS bypasses. In HackMD/CodiMD 1.2.1, a stored XSS flaw in Markdown comment filtering allowed attackers to inject HTML; the platform's CSP still permitted exploitation because it trusted cdnjs.cloudflare.com, enabling an AngularJS client-side template-injection bypass. Organizations should deploy CSP first in Content-Security-Policy-Report-Only mode, collect violations through Reporting endpoints, and continuously test policies for regressions and risky third-party dependencies.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The vulnerability was fixed in a later CodiMD release through a referenced pull request.
A stored XSS flaw in the HackMD/CodiMD Markdown platform's handling of HTML comments allowed attackers to inject arbitrary HTML. HackMD's CSP was bypassed by loading AngularJS from an allowed cdnjs.cloudflare.com source and using client-side template injection to execute JavaScript in document viewers' browsers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.