CVE-2025-46654

Publication date

2025-04-26 00:00:00

Family

mitre

State

PUBLISHED

Description

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.