Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mxm6-v9r6-r94c
  • npm/@nuxtjs/mdc
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration 16 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-cj6r-rrr9-fg82
  • npm/@nuxtjs/mdc
Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering 20 Jul 2025
  • Fix available
  • Severity - 8.3 (High)
GHSA-j82m-pc2v-2484
  • npm/@nuxtjs/mdc
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc 06 Feb 2025
  • Fix available
  • Severity - 9.3 (Critical)