markdown-pdf
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting markdown-pdfpage 1 of 1
- CVE-2018-3770MEDIUMCVSS 5.5✓ Fixed in 9.0.02018-07-20
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
- CVE-2023-0835HIGHCVSS 8.2EG 7.52023-04-04
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
Check whether markdown-pdf is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for markdown-pdf CVEs against the assets you own.
Start Free Scan →