VYPR

Markdownify

by Markdownify Project

CVEs (2)

  • CVE-2022-41709HigOct 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" option enabled.

  • CVE-2022-41710MedNov 3, 2022
    risk 0.36cvss 5.5epss 0.00

    Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough)…