← العودة للجدول
CVE-2026-49493
CVE-2026-49493 — GHSA: Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(),...
📅 2026-06-05
🟠 High 🔥 No GHSA Vulnerability Vulnerability CVSS 8.8

📋 الوصف الكامل

Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled code on the server side when the document is rendered or exported. Fixed in 0.8.28 by parsing bitfield

💻 الأنظمة المتأثرة

GHSA: Markdown Preview

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-49493

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←