CVE-2022-36036

LOW

mdx-mermaid <1.3.0, <2.0.0-rc1 - Code Injection

Title source: llm
STIX 2.1

Description

mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This vulnerability was patched in version(s) 1.3.0 and 2.0.0-rc2. There are currently no known workarounds.

References (2)

Core 2

Scores

CVSS v3 3.6
EPSS 0.0013
EPSS Percentile 31.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (3)
mdx-mermaid_project/mdx-mermaid 2.0.0 rc1
mdx-mermaid_project/mdx-mermaid 0.0.1 - 1.3.0
npm/mdx-mermaid 0 - 1.3.0npm
Published Aug 29, 2022
Tracked Since Feb 18, 2026