Description
vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require('child_process').execSync('calc.exe') on Windows and a similar attack on macOS.
Remediation
References
https://github.com/yoshuawuyts/vmd/issues/137
Related Vulnerabilities
CVE-2021-32854 Vulnerability in npm package textangular
CVE-2020-16041 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-23648 Vulnerability in npm package @braintree/sanitize-url
CVE-2013-7250 Vulnerability in maven package org.projectforge:projectforge-webapp
CVE-2021-21353 Vulnerability in maven package org.webjars.npm:pug-code-gen