Improper Control of Generation of Code ('Code Injection') in mdx-mermaid
Description
Published by the National Vulnerability Database
Aug 29, 2022
Published to the GitHub Advisory Database
Aug 31, 2022
Reviewed
Aug 31, 2022
Last updated
Jan 29, 2023
Impact
Arbitary javascript injection
Modify any mermaid code blocks with the following code and the code inside will execute when the component is loaded by MDXjs
The block below shows a valid mermaid code block
The same block but with the exploit added
Patches
1.3.0 and 2.0.0-rc2
Workarounds
None known
References