Executive brief
A vulnerability exists in a DigitalOcean library used to render Markdown content, which is common in community forums and documentation sites. If the library is misconfigured, an attacker can bypass security restrictions to use unauthorized formatting styles or environment tags. This could allow a regular user to display content that appears to have administrative authority or access restricted layout features.
Technical details
A type confusion vulnerability exists in the @digitalocean/do-markdownit package through version 1.16.1. The 'callout' and 'fence_environment' plugins expect 'allowedClasses' and 'allowedEnvironments' options to be arrays of strings. If these options are incorrectly provided as a single string during configuration, the library performs a '.includes()' check on the string rather than an array membership check. This results in substring matching (e.g., 'pro' matching 'production'), which allows an attacker to bypass intended allow-list constraints by supplying crafted input that satisfies the substring check. This can lead to unauthorized rendering of restricted classes or environments. Developers should ensure these options are validated as arrays or normalized before use.
Affected products
- DigitalOcean community do-markdownit <= 1.16.1
Timeline
- 2025-09-04: other: Vulnerability discovered and PoC created by researcher
- 2025-09-19: disclosed: Advisory published on GitHub/OSV
- 2025-09-19: advisory: NVD entry published