CVE-2025-54075 is a stored cross-site scripting (XSS) vulnerability in @nuxtjs/mdc versions prior to 0.17.2, allowing a malicious Markdown author to inject a base href tag. This enables an attacker to redirect relative URLs to an attacker-controlled origin, facilitating the execution of arbitrary JavaScript within the affected site's context. The vulnerability carries a high CVSS score of 8.3, indicating a network-exploitable flaw with low attack complexity and potential for significant impact across confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nuxt-Modules | Mdc | < 0.17.2CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.