HIGH
markdown-pdf 11.0.0 - Local File Read via Server Side XSS
Published Apr 4, 2023
8.2
HIGHCVSS 3.1
EPSS 0.60%
Description
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
Affected products
- Vendor n/a Product Markdown-Pdf Defaultunaffected
- Version 11.0.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Markdown-Pdf | unaffected |
|
- 11.0.0
No data.
No Red Hat product state for this CVE.
markdown-pdf
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | markdown-pdf | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://fluidattacks.com/advisories/relsb ExploitThird Party Advisory
- https://github.com/advisories/GHSA-qghr-877h-f9jh Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-0835
- https://www.npmjs.com/package/markdown-pdf Product
| Link | Providers | Tags |
|---|---|---|
| https://fluidattacks.com/advisories/relsb | ExploitThird Party Advisory | |
| https://github.com/advisories/GHSA-qghr-877h-f9jh | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-0835 | ||
| https://www.npmjs.com/package/markdown-pdf | Product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Fluid Attacks
Published Apr 4, 2023
Updated Dec 3, 2025
Reserved Feb 14, 2023
Link CVE-2023-0835
CISA Vulnrichment
GHSA-QGHR-877H-F9JH Updated Feb 13, 2025