Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j84q-hxmx-jr5m

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 7.2

Описание

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

EPSS

Процентиль: 24%
0.00079
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
nvd
23 дня назад

Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling remote code execution.

EPSS

Процентиль: 24%
0.00079
Низкий

5.1 Medium

CVSS4

7.2 High

CVSS3

Дефекты

CWE-79