← Back to browse · API

CVE-2021-23639

Severity
CRITICAL
CVSS
9.8
EPSS
0.05329
Risk score
41.07
CISA KEV
No
PoC
No
Published
2021-12-10
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2021-2610, GHSA-X949-7CM6-FM6P
Products
simonhaenisch:md-to-pdf unspecified <5.0.0
Sources
euvd EUVD-2021-2610

Description

The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

References