PT-2026-93790 · Npm · @Nuxtjs/Mdc

CVE-2026-63671

·

Published

2026-09-16

·

Updated

2026-09-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @nuxtjs/mdc versions prior to 0.22.1
Description @nuxtjs/mdc renders untrusted Markdown to a Vue component tree and enables raw HTML by default via parseMarkdown with allowDangerousHtml set to true. The built-in sanitizer, which uses validateProps, validateProp, and unsafeLinkPrefix, contains two gaps that allow the execution of malicious scripts:
  1. The validateProp() function only checks attributes named href or src. This allows an SVG xlink:href attribute (represented as xLinkHref) to contain a javascript: URL, which executes in the page origin when clicked.
  2. The unsafeLinkPrefix denylist compares entries against url.protocol. Since the protocol for data URIs is simply data:, entries like data:text/html are never matched. This allows an iframe src containing data:text/html to bypass sanitization and execute scripts in an opaque origin upon loading.
Recommendations Update @nuxtjs/mdc to version 0.22.1.

Exploit

Fix

Incomplete List of Disallowed Inputs

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63671
GHSA-MXM6-V9R6-R94C

Affected Products

@Nuxtjs/Mdc