CVE-2025-65108

md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library, resulting in remote code execution. This issue has been patched in version 5.2.5.
Configurations

No configuration.

History

21 Nov 2025, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-21 22:16

Updated : 2025-11-25 22:16


NVD link : CVE-2025-65108

Mitre link : CVE-2025-65108

CVE.ORG link : CVE-2025-65108


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')