Vulnerability Description
Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Caret | Caret | All versions |
Related Weaknesses (CWE)
References
- https://research.jfrog.com/vulnerabilities/caret-xss-rce/ExploitThird Party Advisory
- https://research.jfrog.com/vulnerabilities/caret-xss-rce/ExploitThird Party Advisory
FAQ
What is CVE-2022-42967?
CVE-2022-42967 is a vulnerability with a CVSS score of 7.5 (HIGH). Caret is vulnerable to an XSS attack when the user opens a crafted Markdown file when preview mode is enabled. This directly leads to client-side code execution.
How severe is CVE-2022-42967?
CVE-2022-42967 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-42967?
Check the references section above for vendor advisories and patch information. Affected products include: Caret Caret.