Impact
The CLI component of answer‑me‑with‑html attempts to embed content from a code block by reading the source path supplied in src= attributes. The localPath() routine checks the textual value of the path without resolving symbolic links. Attackers can place a symlink in a repository that points to a file outside of the intended directory. When the tool renders the code block, it follows the symlink and reads the external file, embedding its contents in the generated HTML. The result is disclosure of data that was not intended to be shared.
Affected Systems
The vulnerability exists in QingYunA’s answer‑me‑with‑html, version 0.5.0. No other affected versions are documented.
Risk and Exploitability
The CVSS score of 2.0 classifies the flaw as low severity, and the EPSS score is not available, indicating limited knowledge about exploitation frequency. The issue is not listed in CISA’s KEV catalog. Exploitation requires access to a repository that is processed by the tool, so the risk is confined to environments where user‑supplied content is rendered by answer‑me‑with‑html. The impact is primarily data exposure; there is no immediate threat to code execution or denial of service.
OpenCVE Enrichment