CVE-2022-0748
17.03.2022, 12:15
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
Vendor | Product | Version |
---|---|---|
post-loader_project | post-loader | 𝑥 ≤ 2.0.0 |
𝑥
= Vulnerable software versions