Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2024-7739

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2024-7738

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2023-0835

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
Attacker Value
Unknown

CVE-2021-23639

Disclosure Date: December 10, 2021 (last updated October 07, 2023)
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
Attacker Value
Unknown

CVE-2018-3770

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.