Critical severityNVD Advisory· Published Mar 17, 2022· Updated Sep 17, 2024
Arbitrary Code Execution
CVE-2022-0748
Description
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
post-loadernpm | >= 0.0.0 | — |
Affected products
2- post-loader/post-loaderdescription
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-66ww-999q-mffqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0748ghsaADVISORY
- snyk.io/vuln/SNYK-JS-POSTLOADER-2403737ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.