mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Syntax-tree
Syntax-tree mdast-util-to-hast |
|
| Vendors & Products |
Syntax-tree
Syntax-tree mdast-util-to-hast |
Tue, 02 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1. | |
| Title | mdast-util-to-hast unsanitized class attribute | |
| Weaknesses | CWE-20 CWE-915 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-02T15:34:24.293Z
Reserved: 2025-11-28T23:33:56.364Z
Link: CVE-2025-66400
Updated: 2025-12-02T15:34:19.930Z
Status : Awaiting Analysis
Published: 2025-12-01T23:15:53.070
Modified: 2025-12-02T17:16:29.163
Link: CVE-2025-66400
No data.