← العودة للجدول
CVE-2026-50733
CVE-2026-50733 — GHSA: Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown...
📅 2026-06-05
🟠 High 🔥 No GHSA Vulnerability Vulnerability CVSS 8.8

📋 الوصف الكامل

Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll()/eva() helpers) - and can also be triggered through a element injected via raw HTML in markdown. W

💻 الأنظمة المتأثرة

GHSA: Markdown Preview

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-50733

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←