Description
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
Remediation
References
https://github.com/rhysd/Shiba/commit/e8a65b0f81eb04903eedd29500d7e1bedf249eab
https://github.com/rhysd/Shiba/issues/42
Related Vulnerabilities
CVE-2020-6449 Vulnerability in npm package electron
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2018-10237 Vulnerability in maven package com.google.guava:guava
CVE-2013-5960 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2021-43783 Vulnerability in npm package @backstage/plugin-scaffolder-backend