{"id":"GHSA-c942-mfmp-p4fh","summary":"Markdownify subject to Remote Code Execution via malicious markdown file","details":"Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the \"nodeIntegration\" option enabled. There are currently no patched versions and no known workarounds.","aliases":["CVE-2022-41709"],"modified":"2025-05-08T22:10:51Z","published":"2022-10-19T19:00:17Z","database_specific":{"nvd_published_at":"2022-10-19T17:15:00Z","cwe_ids":["CWE-829"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-10-25T19:58:53Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41709"},{"type":"WEB","url":"https://fluidattacks.com/advisories/adams"},{"type":"PACKAGE","url":"https://github.com/amitmerchant1990/electron-markdownify"}],"affected":[{"package":{"name":"electron-markdownify","ecosystem":"npm","purl":"pkg:npm/electron-markdownify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-c942-mfmp-p4fh/GHSA-c942-mfmp-p4fh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}