Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Sjwall

#52634of 53,622
3.6Total CVSS
Vulnerabilities · 1
PT-2022-23132
3.6
2022-08-29
Unknown · Mdx-Mermaid · CVE-2022-36036
**Name of the Vulnerable Software and Affected Versions** mdx-mermaid versions less than 1.3.0 mdx-mermaid versions 2.0.0-rc1 **Description** The issue concerns an arbitrary JavaScript injection potential in mdx-mermaid. This can be exploited by modifying mermaid code blocks with arbitrary code, which will execute when the component is loaded by MDXjs. There are no known workarounds for this issue. **Recommendations** For mdx-mermaid versions less than 1.3.0, update to version 1.3.0 or later. For mdx-mermaid version 2.0.0-rc1, update to version 2.0.0-rc2 or later.