Beveiligingsadvies

CVE-2026-49493

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-05 17:49:52
Laatst bijgewerkt 2026-06-09 14:36:57
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled code on the server side when the document is rendered or exported. Fixed in 0.8.28 by parsing bitfield register definitions with JSON5.parse(), since they are purely data.