Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the "nodeIntegration" option enabled. There are currently no patched versions and no known workarounds.
{
"cwe_ids": [
"CWE-829"
],
"github_reviewed": true,
"github_reviewed_at": "2022-10-25T19:58:53Z",
"nvd_published_at": "2022-10-19T17:15:00Z",
"severity": "HIGH"
}