markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1375 | markdown-pdf version 11.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the Markdown content entered by the user. |
Github GHSA |
GHSA-qghr-877h-f9jh | markdown-pdf vulnerable to local file read via server side cross-site scripting (XSS) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 03 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | markdown-pdf 11.0.0 - Local File Read via Server Side XSS |
Thu, 13 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-12-03T20:12:39.525Z
Reserved: 2023-02-14T00:00:00.000Z
Link: CVE-2023-0835
Updated: 2024-08-02T05:24:34.504Z
Status : Modified
Published: 2023-04-04T23:15:07.310
Modified: 2025-02-13T16:15:37.380
Link: CVE-2023-0835
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA