{"id":"CVE-2021-23639","aliases":["GHSA-x949-7cm6-fm6p","SNYK-JS-MDTOPDF-1657880"],"url":"https://o3.security/vulnerability/CVE-2021-23639","summary":"Code Injection in md-to-pdf.","details":"The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.","published":"2021-12-10T20:15:08.387Z","modified":"2026-07-09T12:33:14.304866Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"md-to-pdf","fixedVersion":"5.0.0"}],"fix":{"url":"https://github.com/simonhaenisch/md-to-pdf/commit/a716259c548c82fa1d3b14a3422e9100619d2d8a","label":"simonhaenisch/md-to-pdf@a716259"},"references":[{"type":"FIX","url":"https://github.com/simonhaenisch/md-to-pdf/commit/a716259c548c82fa1d3b14a3422e9100619d2d8a"},{"type":"FIX","url":"https://github.com/simonhaenisch/md-to-pdf/issues/99"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-MDTOPDF-1657880"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:33:14.304866Z"}}