CVE-2026-11422
Last modified
CVE-2026-11422 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview context to abuse the extension's message passing and invoke arbitrary file writes on the local filesystem.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview context to abuse the extension's message passing and invoke arbitrary file writes on the local filesystem.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| shd101wyy | Markdown Preview Enhanced | < 0.8.27 |
| shd101wyy | crossnote | < 0.9.28 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-11422?
How severe is CVE-2026-11422?
How do I fix CVE-2026-11422?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-11416MoviePilot contains a path traversal vulnerability in the Al…8.1
- CVE-2026-11417OS command injection in the NodejsFunction local bundling pi…7.3
- CVE-2026-11419A path traversal vulnerability exists in the Altium Enterpri…8.8
- CVE-2026-1142A security flaw has been discovered in PHPGurukul News Porta…6.5
- CVE-2026-11420Two path traversal vulnerabilities in the Network Installati…9.8
- CVE-2026-11421The ERP: Complete HR, Accounting & CRM Suite with WooCommerc…6.5
- CVE-2026-11423A path traversal vulnerability exists in the Altium Enterpri…9.4
- CVE-2026-11424A server-side request forgery (SSRF) vulnerability exists in…8.3
- CVE-2026-11425Domoticz versions prior to 2026.3 contains a stored cross-si…4.4
- CVE-2026-11426The UnderConstructionPage PRO plugin for WordPress is vulner…6.5
- CVE-2026-11429Two endpoints in the Vault Service ScriptsController, shared…10
- CVE-2026-1143A weakness has been identified in TOTOLINK A3700R 9.1.2u.582…8.8
Are you affected by CVE-2026-11422?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
