PT-2026-47053 · Unknown · Markdown Preview Enhanced
CVE-2026-11422
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Markdown Preview Enhanced versions 0.8.x
Description
A code injection issue exists in the WaveDrom rendering pipeline. Attackers can execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. This occurs because the content of the wavedrom block is passed without sanitization to the
window.eval() function within the VS Code webview context. This flaw allows attackers to abuse the extension's message passing mechanism to perform arbitrary file writes on the local filesystem.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Markdown Preview Enhanced