Description
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
Remediation
References
https://github.com/yoshuawuyts/vmd/issues/137
Related Vulnerabilities
CVE-2022-36025 Vulnerability in maven package org.hyperledger.besu:evm
CVE-2018-16479 Vulnerability in npm package http-live-simulator
CVE-2020-7788 Vulnerability in maven package org.webjars.npm:ini
CVE-2022-33891 Vulnerability in maven package org.apache.spark:spark-core_2.12
CVE-2020-26258 Vulnerability in maven package com.thoughtworks.xstream:xstream