Description
The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.
Remediation
References
https://snyk.io/vuln/SNYK-JS-POSTLOADER-2403737
Related Vulnerabilities
CVE-2019-10746 Vulnerability in maven package org.webjars.npm:mixin-deep
CVE-2020-7662 Vulnerability in npm package websocket-extensions
CVE-2019-9155 Vulnerability in npm package openpgp
CVE-2020-17532 Vulnerability in maven package org.apache.servicecomb:foundation-config
CVE-2020-11007 Vulnerability in maven package com.shopizer:sm-core-model