Lucene search

K
nodejsMike (n1__)NODEJS:991
HistoryJun 18, 2019 - 11:26 p.m.

Remote Code Execution

2019-06-1823:26:52
Mike (n1__)
www.npmjs.com
14

0.001 Low

EPSS

Percentile

26.5%

Overview

Versions of markdown-pdf prior to 9.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize HTML code in markdown files. If markdown files with malicious HTML are converted to PDF, the resulting PDF file will execute any JavaScript code in the original markdown file. This may allow attackers to execute Remote Code.

Recommendation

Upgrade to version 9.0.0 or later.

References

CPENameOperatorVersion
markdown-pdflt9.0.0

0.001 Low

EPSS

Percentile

26.5%