Description
This is a remote code execution (RCE) vulnerability. Node.js automatically imports **/*.plugin.{js,mjs} files including those from node_modules, so any malicious package with a .plugin.js file could execute arbitrary code when installed or required.
Recommendation
Update the @tygo-van-den-hurk/slyde package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.0.5
- Patched version(s): 0.0.5
References
Could your website be exposed too?
SmartScanner can check your website for Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Improper Control of Generation of Code ('Code Injection') in mdx-mermaid - CVE-2022-36036
- Orval has a code injection via unsanitized x-enum-descriptions in enum generation - CVE-2026-23947
- Improper Control of Generation of Code in doT - CVE-2020-8141
- Orval Mock Generation Code Injection via const - CVE-2026-24132


