Security Advisory

CVE-2021-23639

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-12-10 20:05:16
Last updated 2024-09-17 00:45:43
Assigner snyk
CVSS score 9.8
State PUBLISHED

Description

The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.