Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shd101wyy
Shd101wyy crossnote Shd101wyy markdown Preview Enhanced |
|
| Vendors & Products |
Shd101wyy
Shd101wyy crossnote Shd101wyy markdown Preview Enhanced |
Fri, 05 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview context to abuse the extension's message passing and invoke arbitrary file writes on the local filesystem. | |
| Title | Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering | |
| Weaknesses | CWE-95 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:13:44.203Z
Reserved: 2026-06-05T20:01:11.442Z
Link: CVE-2026-11422
Updated: 2026-06-08T13:09:55.271Z
Status : Awaiting Analysis
Published: 2026-06-05T21:16:29.177
Modified: 2026-06-08T15:16:39.280
Link: CVE-2026-11422
No data.
OpenCVE Enrichment
Updated: 2026-06-07T11:15:44Z