← Back to browse · API

CVE-2022-0748

Severity
CRITICAL
CVSS
9.8
EPSS
0.02089
Risk score
39.93
CISA KEV
No
PoC
No
Published
2022-03-17
Modified
2024-09-17
First seen
2026-08-07
Aliases
EUVD-2022-1336, GHSA-66WW-999Q-MFFQ
Products
n/a:post-loader 0.0.0 <unspecified
Sources
euvd EUVD-2022-1336

Description

The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.

References