CVE-2019-12043: Remarkable Project Remarkable
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintable characters, as demonstrated by a \x0ejavascript: URL.
Affected products
- Remarkable Project Remarkable: version 1.7.1 only
Published 2019-05-13. Last modified 2026-06-17.