Critical severity9.8NVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026
CVE-2022-0748
CVE-2022-0748
Description
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
post-loadernpm | >= 0.0.0 | — |
Affected products
3- cpe:2.3:a:post-loader_project:post-loader:*:*:*:*:*:node.js:*:*Range: <=2.0.0
- post-loader/post-loaderdescription
Patches
Vulnerability mechanics
References
3- snyk.io/vuln/SNYK-JS-POSTLOADER-2403737nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-66ww-999q-mffqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0748ghsaADVISORY
News mentions
0No linked articles in our index yet.