Impact
The sanitizer in @nuxtjs/mdc fails to strip SVG xlink:href attributes and data:text/html URLs. Because the validator only checks the href and src attributes, an SVG element with a xlink:href can contain a javascript: URL that executes in the page origin when selected. Similarly, data:text/html is only compared to the data: protocol, allowing an iframe src with data:text/html to survive and run code in an opaque origin when loaded. Consequently, an attacker can embed malicious JavaScript in ordinary markdown, which will run in a visitor’s browser as a cross‑site scripting attack, potentially stealing data or defacing pages.
Affected Systems
Environments that use the @nuxtjs/mdc library (nuxt-content:mdc) with versions older than 0.22.1. The vulnerability is present in all builds prior to the 0.22.1 release, regardless of the surrounding Nuxt Content configuration. Any site or application that processes user‑supplied markdown through this library and relies on the default allowDangerousHtml setting is affected.
Risk and Exploitability
The CVSS score is 8.1, indicating high severity, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low to moderate risk of exploitation. The likely attack vector requires an attacker who can inject untrusted markdown into the rendering pipeline; the flaw is exploitable via the default configuration that processes dangerous HTML. If an application unnecessarily allows untrusted markdown to be rendered, an attacker can deploy malicious SVG or data URLs to execute code in the client context, but widespread exploitation is constrained by the need for such injection opportunities and the low probability indicated by EPSS.
OpenCVE Enrichment
Github GHSA