VDB
Sign up
MEDIUM5.5

GHSA-p7c9-jqhq-vr3v

Remote Code Execution in markdown-pdf

Quick fix

GHSA-p7c9-jqhq-vr3v — markdown-pdf: upgrade to the fixed version with the command below.

npm install markdown-pdf@9.0.0

Details

Versions of `markdown-pdf` prior to 9.0.0 are vulnerable to Remote Code Execution. The package fails to sanitize HTML code in markdown files. If markdown files with malicious HTML are converted to PDF, the resulting PDF file will execute any JavaScript code in the original markdown file. This may allow attackers to execute Remote Code.

## Recommendation

Upgrade to version 9.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/markdown-pdf
Introduced in: 0Fixed in: 9.0.0
Fixnpm install markdown-pdf@9.0.0

References