joemccann / dillinger

The last Markdown editor, ever.
https://dillinger.io
MIT License
7.9k stars 1.1k forks source link

update md-to-pdf to prevent RCE via javascript front-matter #821

Closed simonhaenisch closed 2 years ago

simonhaenisch commented 2 years ago

For context see https://github.com/simonhaenisch/md-to-pdf/issues/99.

joemccann commented 2 years ago

awesome thanks!

simonhaenisch commented 2 years ago

@joemccann seems like you haven't deployed this change yet? at least I can still use the vulnerability...

joemccann commented 2 years ago

Yeah I haven't - super low priority as the servers are stateless. Not much to hack into

On Tue, Sep 28, 2021 at 12:45 AM Simon Hänisch @.***> wrote:

@joemccann https://github.com/joemccann seems like you haven't deployed this change yet? at least I can still use the vulnerability...

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/joemccann/dillinger/pull/821#issuecomment-928940720, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAALY2SKQAUBABUGEJNV7Z3UEFXDLANCNFSM5EVVMX3Q . Triage notifications on the go with GitHub Mobile for iOS https://apps.apple.com/app/apple-store/id1477376905?ct=notification-email&mt=8&pt=524675 or Android https://play.google.com/store/apps/details?id=com.github.android&referrer=utm_campaign%3Dnotification-email%26utm_medium%3Demail%26utm_source%3Dgithub.