Executive brief
md-to-pdf is a Node.js library that converts Markdown documents to PDF files. The library failed to disable the JavaScript engine in the gray-matter YAML front-matter parser, allowing attackers to execute arbitrary code when processing Markdown files. An attacker who controls Markdown input can run arbitrary system commands with the privileges of the application.
Affected products
- Simon Hänisch md-to-pdf before 5.0.0
Timeline
- 2021-09-22: disclosed: Issue #99 opened on GitHub
- 2021-12-10: advisory: NVD published CVE-2021-23639
- 2021-12-16: patched: GHSA advisory published; version 5.0.0 available with fix