Description
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
Remediation
References
https://github.com/rhysd/Shiba/commit/e8a65b0f81eb04903eedd29500d7e1bedf249eab
https://github.com/rhysd/Shiba/issues/42
Related Vulnerabilities
CVE-2019-10158 Vulnerability in maven package org.infinispan:infinispan-spring5-common
CVE-2023-22477 Vulnerability in npm package mercurius
CVE-2013-7370 Vulnerability in npm package connect
CVE-2017-2600 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-7758 Vulnerability in npm package browserless-chrome