Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.
Reported upstream for jupyterlab: https://github.com/jupyterlab/jupyterlab/issues/16864
Fixed upstream in https://github.com/jupyterlab/jupyterlab/commit/e707512050c9b54e4a7a76c313f64cf0a9c4abc2 I'm waiting for the next release.