Junglewise Threat Intelligence

CVE-2021-23639: md-to-pdf code injection in gray-matter parsing

CVE-2021-23639 · Severity: low · CVSS 3.1 · Published 2021-12-16

Vendors: npm.

Executive brief

md-to-pdf is a Node.js library that converts Markdown documents to PDF files. The library failed to disable the JavaScript engine in the gray-matter YAML front-matter parser, allowing attackers to execute arbitrary code when processing Markdown files. An attacker who controls Markdown input can run arbitrary system commands with the privileges of the application.

Affected products

  • Simon Hänisch md-to-pdf before 5.0.0

Timeline

  • 2021-09-22: disclosed: Issue #99 opened on GitHub
  • 2021-12-10: advisory: NVD published CVE-2021-23639
  • 2021-12-16: patched: GHSA advisory published; version 5.0.0 available with fix

References

Related threats