Executive brief
mdx-mermaid is a library that integrates Mermaid diagram syntax into MDX markdown documents. An attacker can inject arbitrary JavaScript code into mermaid code blocks that executes when the document is rendered, potentially allowing them to steal data or manipulate page content if they can control the markdown source.
Technical details
The vulnerability is a code injection flaw (CWE-94) in how mdx-mermaid processes mermaid code blocks. The library fails to sanitize template literal expressions embedded in mermaid diagrams, allowing an attacker to break out of the diagram syntax by injecting JavaScript functions wrapped in template literal syntax (backticks and function calls). The attack requires local file access or ability to modify the markdown source (PR:L), but requires no user interaction and occurs during component rendering. Exploitation results in arbitrary JavaScript execution within the MDX rendering context. Patches are available in versions 1.3.0 and 2.0.0-rc2.
Affected products
- sjwall mdx-mermaid 0.0.1 through 1.2.3, and 2.0.0-rc1
Timeline
- 2022-08-22: disclosed
- 2022-08-31: patched: Versions 1.3.0 and 2.0.0-rc2 released with fix