HIGH8.3npm
GHSA-cj6r-rrr9-fg82· CVE-2025-54075Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
Modified: 9/10/2026
package
pkg:npm/%40nuxtjs/mdc
Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
Modified: 9/10/2026
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
Modified: 2/13/2025
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
Modified: 9/16/2026