Impact
The affected function, lds in markdown’s md.c, contains an out‑of‑bounds read that can be triggered by a crafted input. This flaw permits an attacker to read memory beyond its intended bounds, potentially leaking confidential data or aiding further exploitation. The weakness aligns with input validation and bounds checking failures identified as CWE‑119 and CWE‑125, and the impact is a remote data disclosure if an attacker can supply malicious markdown content.
Affected Systems
The vulnerability affects the open‑source 92181 markdown project. No specific version numbers are supplied because the project uses a rolling release model, so affected releases are not enumerated. Users should assume all current and previous builds prior to the patch could be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS information is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower near‑term exploitation pressure. An attacker can execute the vulnerability remotely by submitting crafted markdown content to any service that processes it. The risk remains until the designated patch is applied.
OpenCVE Enrichment