Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6624 | mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when the component is loaded by MDXjs. This vulnerability was patched in version(s) 1.3.0 and 2.0.0-rc2. There are currently no known workarounds. |
Github GHSA |
GHSA-rvgm-35jw-q628 | Improper Control of Generation of Code ('Code Injection') in mdx-mermaid |
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T17:41:03.862Z
Reserved: 2022-07-15T00:00:00.000Z
Link: CVE-2022-36036
Updated: 2024-08-03T09:52:00.316Z
Status : Modified
Published: 2022-08-29T18:15:09.803
Modified: 2024-11-21T07:12:14.183
Link: CVE-2022-36036
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA