CVE-2018-3770: Markdown-PDF Project Markdown-PDF
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
Affected products
- Markdown-PDF Project Markdown-PDF: before 9.0.0 (fixed in 9.0.0)
Published 2018-07-20. Last modified 2026-06-17.