yuriisanin/CVE-2022-45025

[PoC] Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom)

markdownexploitrcecvecommand-injection
This is stars and forks stats for /yuriisanin/CVE-2022-45025 repository. As of 12 May, 2024 this repository has 89 stars and 19 forks.

CVE-2022-45025 Command injection via PDF import in Markdown Preview Enhanced (VSCode, Atom) Description The Mume markdown tool library was vulnerable to command injection due to use of spawn command with {shell: true} option. This could allow an attacker to achieve arbitary code execution by tricking victim into opening specially crafted Markdown file using VSCode or Atom. The library powers Markdown Preview Enhanced plugin for both VSCode and Atom. Vulnerable code snippet: const task = spawn( ...
Read on GithubGithub Stats Page
repotechsstarsweeklyforksweekly
mark-when/markwhenHTMLVueTypeScript3.1k01150
mrzool/letter-boilerplateTeXMakefile4420780
secure-77/PerliteCSSPHPJavaScript7280720
lambdaclass/pluto-to-bookdownJulia1000
kkent030315/CVE-2022-42046C++Rust1570260
preservim/vim-pencilVim Script1.5k+1370
seanpm2001/Why-you-should-avoid-Google-NewsMarkdownHTML3020
seanpm2001/Problems-with-the-Google-Knowledge-GraphMarkdownHTML2010
seanpm2001/Why-you-should-stop-using-Google-ImagesMarkdownHTML2010
seanpm2001/Why-you-should-stop-using-Google-ShoppingMarkdownHTML2010