VDB
Sign up

package

npm/@nuxtjs/mdc

pkg:npm/%40nuxtjs/mdc

HIGH8.1npm
GHSA-mxm6-v9r6-r94c· CVE-2026-63671

@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration

Modified: 9/16/2026