PT-2026-47053 · Unknown · Markdown Preview Enhanced

CVE-2026-11422

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Markdown Preview Enhanced versions 0.8.x
Description A code injection issue exists in the WaveDrom rendering pipeline. Attackers can execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. This occurs because the content of the wavedrom block is passed without sanitization to the window.eval() function within the VS Code webview context. This flaw allows attackers to abuse the extension's message passing mechanism to perform arbitrary file writes on the local filesystem.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11422

Affected Products

Markdown Preview Enhanced