← volver
CVE-2025-65108criticalCWE-94

md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 10epss 0.9%
probabilidad de explotación
0.9%top 42% de las CVE
explotación observada
noninguna fuente lo reporta
md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library, resulting in remote code execution. This issue has been patched in version 5.2.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Productos afectados
simonhaenisch · md-to-pdf