VYPR
Unrated severityNVD Advisory· Published Jan 11, 2023· Updated Apr 8, 2025

XSS in Caret markdown editor leads to remote code execution when viewing crafted Markdown files

CVE-2022-42967

Description

Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.