Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2023-0835
Disclosure Date: April 04, 2023 (last updated February 24, 2025)
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
0
Attacker Value
Unknown
CVE-2021-23639
Disclosure Date: December 10, 2021 (last updated October 07, 2023)
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
0
Attacker Value
Unknown
CVE-2018-3770
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
0