Description
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
Remediation
References
https://github.com/yoshuawuyts/vmd/issues/137
Related Vulnerabilities
CVE-2023-3635 Vulnerability in maven package com.squareup.okio:okio
CVE-2021-21160 Vulnerability in npm package electron
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2023-22465 Vulnerability in maven package org.http4s:http4s-core_3
CVE-2022-21186 Vulnerability in npm package @acrontum/filesystem-template