CVE-2021-23639
CRITICALmd-to-pdf < 5.0.0 - Remote Code Execution via Gray-Matter Front Matter Parsing
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-23639. PoCs published by MohandAcherir.
AI-analyzed exploit summary The repository contains a functional Python exploit for CVE-2021-23639, targeting the md-to-pdf library. The exploit leverages the gray-matter library's JS engine to achieve Remote Code Execution (RCE) via crafted front matter content.
Description
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
Exploits (1)
The repository contains a functional Python exploit for CVE-2021-23639, targeting the md-to-pdf library. The exploit leverages the gray-matter library's JS engine to achieve Remote Code Execution (RCE) via crafted front matter content.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H