Medium severity4.9NVD Advisory· Published Apr 26, 2025· Updated Jun 17, 2026
CVE-2025-46654
CVE-2025-46654
Description
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/hackmdio/codimd/issues/1910nvdExploitIssue Tracking
- github.com/zast-ai/vulnerability-reports/blob/main/formidable/file_upload/report.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.