Description
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
Remediation
References
https://github.com/yoshuawuyts/vmd/issues/137
Related Vulnerabilities
CVE-2021-46708 Vulnerability in npm package swagger-ui
CVE-2020-28246 Vulnerability in npm package formio
CVE-2023-47322 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2023-38687 Vulnerability in npm package svelecte
CVE-2019-10769 Vulnerability in maven package org.webjars.npm:safer-eval