CVE-2022-36036
29.08.2022, 18:15
mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This vulnerability was patched in version(s) 1.3.0 and 2.0.0-rc2. There are currently no known workarounds.
Vendor | Product | Version |
---|---|---|
mdx-mermaid_project | mdx-mermaid | 0.0.1 ≤ 𝑥 < 1.3.0 |
mdx-mermaid_project | mdx-mermaid | 2.0.0:rc1 |
𝑥
= Vulnerable software versions
References