Vulnerability Description
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Markdown To Pdf Project | Markdown To Pdf | < 5.0.0 |
References
- https://github.com/simonhaenisch/md-to-pdf/commit/a716259c548c82fa1d3b14a3422e91PatchThird Party Advisory
- https://github.com/simonhaenisch/md-to-pdf/issues/99ExploitIssue TrackingPatch
- https://snyk.io/vuln/SNYK-JS-MDTOPDF-1657880ExploitPatchThird Party Advisory
- https://github.com/simonhaenisch/md-to-pdf/commit/a716259c548c82fa1d3b14a3422e91PatchThird Party Advisory
- https://github.com/simonhaenisch/md-to-pdf/issues/99ExploitIssue TrackingPatch
- https://snyk.io/vuln/SNYK-JS-MDTOPDF-1657880ExploitPatchThird Party Advisory
FAQ
What is CVE-2021-23639?
CVE-2021-23639 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
How severe is CVE-2021-23639?
CVE-2021-23639 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-23639?
Check the references section above for vendor advisories and patch information. Affected products include: Markdown To Pdf Project Markdown To Pdf.