PT-2022-26040 · Unknown · Markdownify

Carlos Bello

·

Published

2022-11-03

·

Updated

2025-04-22

·

CVE-2022-41710

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Markdownify version 1.4.1
Description The issue allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. This is possible because the application does not have a Content Security Policy (CSP) or at least not a strict enough one, and/or does not properly validate the contents of markdown files before rendering them.
Recommendations For Markdownify version 1.4.1, consider implementing a strict Content Security Policy (CSP) and properly validating the contents of markdown files before rendering them to prevent exploitation. As a temporary workaround, consider restricting the use of Markdownify until a patch is available.

Exploit

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2022-41710
GHSA-QQHF-XFHW-7884

Affected Products

Markdownify