Junglewise Threat Intelligence

CVE-2025-66400: mdast-util-to-hast unsanitized class attribute

CVE-2025-66400 · Severity: low · CVSS 3.1 · Published 2025-12-02

Vendors: npm.

Executive brief

mdast-util-to-hast is a JavaScript utility that converts markdown-formatted text into HTML. A flaw in the library allows attackers to inject extra CSS classes into code blocks by embedding HTML character references in markdown source. If a website applies CSS rules or JavaScript event handlers to those injected class names, an attacker could disguise or alter the appearance of code blocks, or trigger unintended behaviors on the page.

Technical details

mdast-util-to-hast contains an improper input sanitization vulnerability in its handling of the `lang` attribute on code blocks. The bug was introduced in version 13.0.0 when legacy code splitting on whitespace was removed. An attacker can craft markdown containing HTML character references (e.g., ` ` for space) in the language specifier to inject arbitrary class names into the generated HTML `class` attribute of code elements. For example, the markdown `` js xss `` produces `<code class="language-js xss">` instead of the intended single class. This allows injection of unprefixed CSS classes that can be styled or targeted by page JavaScript if matching rules exist. The vulnerability affects versions 13.0.0 through 13.2.0 and was patched in version 13.2.1. No authentication or user interaction is required; any content processing markdown with this library is affected.

Affected products

  • syntax-tree mdast-util-to-hast 13.0.0 through 13.2.0

Timeline

  • 2025-12-01: disclosed: GHSA-4fh9-h7wg-q85m published
  • 2025-12-02: patched: Fixed in version 13.2.1

References