PT-2026-47025 · Shd101Wyy · Markdown Preview Enhanced

Published

2026-06-05

·

Updated

2026-06-05

·

CVE-2026-50733

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll()/eva() helpers) - and can also be triggered through a

Fix

Eval Injection

Weakness Enumeration

Related Identifiers

CVE-2026-50733

Affected Products

Markdown Preview Enhanced