Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2023-0835

Disclosure Date: April 04, 2023 (last updated February 24, 2025)
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
Attacker Value
Unknown

CVE-2021-23639

Disclosure Date: December 10, 2021 (last updated October 07, 2023)
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
Attacker Value
Unknown

CVE-2018-3770

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.