Medium · 5.1 Node.js & npm GHSA-mxm6-v9r6-r94c CVE-2026-63671
XSS Sanitizer Bypass in @nuxtjs/mdc via SVG xlink:href and data:text/html
A cross-site scripting vulnerability (CVE-2026-63671) in @nuxtjs/mdc before 0.22.1 allows untrusted Markdown to bypass URL sanitization via SVG xlink:href attributes and data:text/html iframe sources, executing attacker-controlled script in the page context.
AI summary
A cross-site scripting (XSS) vulnerability has been disclosed in @nuxtjs/mdc, a tool for rendering Markdown as interactive Vue components. Tracked as CVE-2026-63671 (GHSA-mxm6-v9r6-r94c), the issue allows attackers to bypass the library's built-in URL sanitizer when processing untrusted Markdown content, potentially executing arbitrary script in the context of the affected page. The vulnerability has been fixed in version 0.22.1.
What happened
@nuxtjs/mdc parses Markdown with allowDangerousHtml enabled by default and relies on sanitization functions (validateProps, validateProp, and unsafeLinkPrefix) to strip executable URLs from untrusted Markdown before rendering. Two specific gaps were found in this sanitization logic that allow malicious content to slip through and execute in the browser.
Technical cause
The sanitizer has two sibling gaps. First, validateProp only checks attributes literally named href or src, but an SVG attribute written as xLinkHref (representing xlink:href) is not checked, allowing a javascript: URL in that attribute to execute in the page's own origin when the element is interacted with. Second, the denylist for data:text/html values compares only against the URL's protocol component, which is simply data:. This means an iframe with a src of data:text/html survives sanitization entirely and executes when the iframe loads, running in an opaque origin. Other dangerous constructs — plain href javascript: URLs, srcdoc, object, script, and base elements — are already correctly blocked by the existing sanitizer; these two paths are narrow, specific exceptions.
Why it matters
Any application that renders Markdown from untrusted or user-supplied sources using @nuxtjs/mdc with default settings is exposed to script execution in the browser. This can lead to session hijacking, credential theft, or other actions performed in the security context of a logged-in user, depending on how the rendered content is displayed and what privileges the viewing user holds.
Who is affected
Any project using the @nuxtjs/mdc npm package to render Markdown from untrusted sources, prior to version 0.22.1, is affected. Risk is concentrated in applications that accept Markdown input from users or external sources and render it with the default allowDangerousHtml configuration.
Affected versions
All versions of @nuxtjs/mdc prior to 0.22.1 are affected.
Fixes and mitigation
The issue is fixed in @nuxtjs/mdc version 0.22.1. Projects using this package should update to this version or later.
Recommended action
Update @nuxtjs/mdc to version 0.22.1. If immediate updating is not possible, consider disabling allowDangerousHtml for untrusted Markdown sources and apply additional output sanitization as a temporary mitigation until the update can be applied.
PatchBriefing score
5.1 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Why this score
This vulnerability carries a PatchBriefing score of 5.1, driven primarily by its CVSS base score of 8.1, reflecting network-exploitable, low-complexity, unauthenticated conditions that can compromise confidentiality and integrity. The score is moderated because the attack requires user interaction (e.g., clicking a crafted link or loading content containing the malicious markup), there is no evidence of known exploitation in the wild, no public exploit code has been identified, and a fix is already available. EPSS data indicates a low probability of near-term exploitation.
Affected versions
- @nuxtjs/mdc < 0.22.1
- vulnerable
- ≥ 0.22.1
- patched
Reported fixes
The issue is fixed in @nuxtjs/mdc version 0.22.1. Projects using this package should update to this version or later.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email