Description
MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value represented as xLinkHref to retain a javascript: URL that executes in the page origin when selected. The data:text/html denylist entries are also compared against url.protocol, which is only data:, so an iframe src containing data:text/html survives sanitization and executes in an opaque origin when loaded. Plain href javascript: URLs, srcdoc, object, script, and base elements are already blocked, making these two paths specific sibling gaps in the sanitizer. This issue is fixed in version 0.22.1.
Published: 2026-09-16
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting via untrusted markdown
Action: Apply Patch
AI Analysis

Impact

The sanitizer in @nuxtjs/mdc fails to strip SVG xlink:href attributes and data:text/html URLs. Because the validator only checks the href and src attributes, an SVG element with a xlink:href can contain a javascript: URL that executes in the page origin when selected. Similarly, data:text/html is only compared to the data: protocol, allowing an iframe src with data:text/html to survive and run code in an opaque origin when loaded. Consequently, an attacker can embed malicious JavaScript in ordinary markdown, which will run in a visitor’s browser as a cross‑site scripting attack, potentially stealing data or defacing pages.

Affected Systems

Environments that use the @nuxtjs/mdc library (nuxt-content:mdc) with versions older than 0.22.1. The vulnerability is present in all builds prior to the 0.22.1 release, regardless of the surrounding Nuxt Content configuration. Any site or application that processes user‑supplied markdown through this library and relies on the default allowDangerousHtml setting is affected.

Risk and Exploitability

The CVSS score is 8.1, indicating high severity, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low to moderate risk of exploitation. The likely attack vector requires an attacker who can inject untrusted markdown into the rendering pipeline; the flaw is exploitable via the default configuration that processes dangerous HTML. If an application unnecessarily allows untrusted markdown to be rendered, an attacker can deploy malicious SVG or data URLs to execute code in the client context, but widespread exploitation is constrained by the need for such injection opportunities and the low probability indicated by EPSS.

Generated by OpenCVE AI on September 18, 2026 at 02:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @nuxtjs/mdc to version 0.22.1 or later
  • If an upgrade is not immediately possible, disable the allowDangerousHtml option when parsing markdown so that only safe HTML and plain text are rendered
  • Filter or sanitize all untrusted markdown content with a trusted sanitizer or whitelist approach before handing it to the renderer

Generated by OpenCVE AI on September 18, 2026 at 02:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mxm6-v9r6-r94c @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Nuxt-content
Nuxt-content mdc
Vendors & Products Nuxt-content
Nuxt-content mdc

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and unsafeLinkPrefix to remove executable URLs from untrusted Markdown. validateProp checks only attributes named href or src, allowing an SVG xlink:href value represented as xLinkHref to retain a javascript: URL that executes in the page origin when selected. The data:text/html denylist entries are also compared against url.protocol, which is only data:, so an iframe src containing data:text/html survives sanitization and executes in an opaque origin when loaded. Plain href javascript: URLs, srcdoc, object, script, and base elements are already blocked, making these two paths specific sibling gaps in the sanitizer. This issue is fixed in version 0.22.1.
Title @nuxtjs/mdc: the URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
Weaknesses CWE-184
CWE-79
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Nuxt-content Mdc
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:54:37.852Z

Reserved: 2026-07-17T14:47:08.032Z

Link: CVE-2026-63671

cve-icon Vulnrichment

Updated: 2026-09-18T17:54:09.425Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:17:40.100

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-63671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')