VYPR
Vendor

Markdownify Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2022-41709HigOct 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" option enabled.

  • CVE-2022-41710MedNov 3, 2022
    risk 0.36cvss 5.5epss 0.00

    Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a CSP policy (or at least not strict enough)…