Skip to main content

Snyk Labs

Featured article

Same href, different syntax: XSS across content parsers

Catalin Iovita


We’ll explore how URL handling works across Markdown parsers and math renderers, and why validation order matters. We'll dig into a bypass in Goldmark, a popular Go Markdown parser, and see how math rendering can introduce a separate attack surface.

Latest Demos and Research

Featured Video

Vibe Coding with Claude Agentic AI Tool

Experiments

Where security meets curiosity

Explore projects from Snyk Labs

ai-bom-scan

Python

A tool to scan Snyk AI-BOMs for specific components in Snyk organizations

March 10, 2026


7

10

0

ai-promoter

Python

A simple web application that makes it easy for employees at your company to see and promote content you're creating!

October 30, 2025


3

1

0

mcp-server-nodejs-api-docs

JavaScript

MCP Server for the Node.js API documentation

March 14, 2026


6

4

0