CVE Vulnerabilities

CVE-2022-41709

Published: Oct 19, 2022 | Modified: Oct 20, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the nodeIntegration option enabled.

Affected Software

Name Vendor Start Version End Version
Markdownify Markdownify_project 1.4.1 (including) 1.4.1 (including)

References