CVE-2025-46654

Published
View on NVD ↗
CVSS v3
4.9
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file.

CodiMD - Realtime collaborative markdown notes on all platforms.
GitHubGitHub
10.1K