Description
markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
Remediation
References
https://fluidattacks.com/advisories/relsb/
https://www.npmjs.com/package/markdown-pdf/
Related Vulnerabilities
CVE-2018-6561 Vulnerability in npm package dijit
CVE-2020-28424 Vulnerability in npm package s3-kilatstorage
CVE-2021-39134 Vulnerability in npm package @npmcli/arborist
CVE-2022-36007 Vulnerability in maven package com.github.jlangch:venice
CVE-2021-41571 Vulnerability in maven package org.apache.pulsar:pulsar