Executive brief
md-to-pdf is a Node.js library used to convert Markdown documents to PDF files. When processing Markdown with malicious front matter (header metadata), the library executes arbitrary JavaScript code, allowing an attacker to run system commands on the server. This poses a critical risk for web services or cloud applications that accept user-uploaded Markdown files for conversion.
Technical details
md-to-pdf uses the gray-matter library to parse YAML front matter blocks in Markdown files. Gray-matter supports a JavaScript engine that can be triggered by special front matter delimiters (---javascript or ---js), causing it to evaluate the front matter contents as executable JavaScript code. When user-controlled Markdown is passed to md-to-pdf without proper sanitization, an attacker can craft malicious front matter using these delimiters to inject arbitrary JavaScript that executes in the converter process with full node privileges. The vulnerability requires no authentication or user interaction—an attacker simply provides malicious Markdown content. Successful exploitation enables remote code execution (RCE), including command execution via Node.js require() calls (e.g., child_process.execSync()). The vulnerability affects all versions prior to 5.2.5, which includes a fix to properly disable or override the JavaScript engine in gray-matter.
Affected products
- simonhaenisch md-to-pdf before 5.2.5
Timeline
- 2025-11-20: disclosed: Vulnerability publicly disclosed via GitHub Security Advisory GHSA-547r-qmjm-8hvw
- 2025-11-20: patched: Fix released in version 5.2.5; patch commit 46bdcf2051c8d1758b391c1353185a179a47a4d9 overrides gray-matter JavaScript engine