CVE-2022-45026

CRITICAL

Markdown Preview Enhanced 0.6.5 and 0.19.6 - OS Command Injection during GFM Export

Title source: llm
STIX 2.1

Description

An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Third Party Advisory
https://github.com/shd101wyy/vscode-markdown-preview-enhanced/issues/640

Scores

CVSS v3 9.8
EPSS 0.0095
EPSS Percentile 56.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
markdown_preview_enhanced_project/markdown_preview_enhanced 0.6.5 (2 CPE variants)
markdown_preview_enhanced_project/markdown_preview_enhanced 0.19.6 (2 CPE variants)
Published Dec 07, 2022
Tracked Since Feb 18, 2026