Gatsbyjs

Gatsby-plugin-mdx

1 Schwachstelle gefunden

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.91%
  • Veröffentlicht 10.06.2022 20:15:08
  • Zuletzt bearbeitet 29.09.2026 15:50:31

The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization...