Description
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
Remediation
References
https://github.com/rhysd/Shiba/commit/e8a65b0f81eb04903eedd29500d7e1bedf249eab
https://github.com/rhysd/Shiba/issues/42
Related Vulnerabilities
CVE-2019-11808 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2021-23362 Vulnerability in maven package org.webjars.npm:hosted-git-info
CVE-2020-15232 Vulnerability in maven package org.mapfish.print:print-standalone
CVE-2021-37713 Vulnerability in npm package tar
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc8