Description
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
Remediation
References
https://snyk.io/vuln/SNYK-JS-POSTLOADER-2403737
Related Vulnerabilities
CVE-2011-1026 Vulnerability in maven package org.apache.archiva:archiva
CVE-2022-31147 Vulnerability in npm package jquery-validation
CVE-2022-23461 Vulnerability in npm package jodit
CVE-2020-7637 Vulnerability in maven package org.webjars.npm:class-transformer
CVE-2022-23622 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates