Vulnerabilities/

Unsanitized JavaScript code injection possible in gatsby-plugin-mdx

Severity:
High

Description

The gatsby-plugin-mdx plugin prior to versions 3.15.2 and 2.14.1 passes input through to the gray-matter npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized.

Recommendation

Update the gatsby-plugin-mdx package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
gatsby-plugin-mdx
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing