md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library, resulting in remote code execution. This issue has been patched in version 5.2.5.
History

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Simonhaenisch
Simonhaenisch md-to-pdf
Vendors & Products Simonhaenisch
Simonhaenisch md-to-pdf

Fri, 21 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
Description md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute arbitrary code in the Markdown to PDF converter process of md-to-pdf library, resulting in remote code execution. This issue has been patched in version 5.2.5.
Title md-to-pdf is vulnerable to arbitrary JavaScript code execution when parsing front matter
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-11-21T21:52:02.729Z

Reserved: 2025-11-17T20:55:34.694Z

Link: CVE-2025-65108

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-21T22:16:33.317

Modified: 2025-11-21T22:16:33.317

Link: CVE-2025-65108

cve-icon Redhat

No data.