Description
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
Remediation
References
https://github.com/yoshuawuyts/vmd/issues/137
Related Vulnerabilities
CVE-2016-8749 Vulnerability in maven package org.apache.camel:camel-jacksonxml
CVE-2019-25102 Vulnerability in npm package simple-markdown
CVE-2020-36185 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-7780 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.13