Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-24981

Опубликовано: 06 фев. 2025
Источник: nvd
CVSS3: 9.3
EPSS Низкий

Описание

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. In affected versions unsafe parsing logic of the URL from markdown can lead to arbitrary JavaScript code due to a bypass to the existing guards around the javascript: protocol scheme in the URL. The parsing logic implement in props.ts maintains a deny-list approach to filtering potential malicious payload. It does so by matching protocol schemes like javascript: and others. These security guards can be bypassed by an adversarial that provides JavaScript URLs with HTML entities encoded via hex string. Users who consume this library and perform markdown parsing from unvalidated sources could result in rendering vulnerable XSS anchor links. This vulnerability has been addressed in version 0.13.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 59%
0.0038
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.3
github
около 1 года назад

Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc

EPSS

Процентиль: 59%
0.0038
Низкий

9.3 Critical

CVSS3

Дефекты

CWE-79