simonhaenisch

2 exploits Active since Dec 2021
CVE-2021-23639 WRITEUP CRITICAL WRITEUP
md-to-pdf < 5.0.0 - Remote Code Execution via Gray-Matter Front Matter Parsing
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
CVSS 9.8
CVE-2025-65108 WRITEUP CRITICAL WRITEUP
md-to-pdf < 5.2.5 - Remote Code Execution via Markdown Front-Matter JavaScript Delimiter
md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library, resulting in remote code execution. This issue has been patched in version 5.2.5.
CVSS 10.0