Executive brief
zmarkdown is a Markdown processing library used to convert Markdown content into HTML and LaTeX documents. A local file inclusion vulnerability allowed attackers to reference and include arbitrary image files from the host machine (e.g., /tmp/img.png) within generated LaTeX documents, potentially exposing sensitive files. The issue has been patched by introducing a default option to replace invalid paths with a placeholder image instead of including host files directly.
Technical details
The vulnerability is a path traversal / local file inclusion (CWE-22) affecting zmarkdown's image processing during LaTeX generation. When processing Markdown image syntax like , the library would directly attempt to include files from the specified file system path in the generated LaTeX output, without proper path validation or sanitization. The attack requires only that an attacker control or influence the Markdown content being processed (no network interaction or authentication bypass needed). An attacker can reference known file paths to include arbitrary local files in LaTeX output. The vulnerability has been patched in version 10.1.3, which introduced a new option (now default) to replace invalid/unsafe paths with a default placeholder image instead of including host files directly.
Affected products
- Zeste de Savoir zmarkdown < 10.1.3
Timeline
- 2024-02-03: disclosed: Advisory GHSA-mq6v-w35g-3c97 published on GitHub
- 2024-02-03: patched: Patched in version 10.1.3