9.8
CVSSv3

CVE-2022-45025

Published: 07/12/2022 Updated: 08/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom exists to contain a command injection vulnerability via the PDF file import function.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

markdown preview enhanced project markdown preview enhanced 0.19.6

markdown preview enhanced project markdown preview enhanced 0.6.5

Github Repositories

[PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)

CVE-2022-45025 Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom) Description The Mume markdown tool library was vulnerable to command injection due to use of spawn command with {shell: true} option This could allow an attacker to achieve arbitary code execution by tricking victim into opening specially crafted Markdown file using VSCode or Atom The