漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering
Vulnerability Description
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview context to abuse the extension's message passing and invoke arbitrary file writes on the local filesystem.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
Vulnerability Title
Markdown Preview Enhanced 安全漏洞
Vulnerability Description
Markdown Preview Enhanced是Yiyi Wang个人开发者的一个超级强大标记扩展。 Markdown Preview Enhanced 0.8.x版本存在安全漏洞,该漏洞源于WaveDrom渲染管道中代码注入,导致攻击者通过嵌入恶意内容执行任意JavaScript。
CVSS Information
N/A
Vulnerability Type
N/A