The Markdownify Project maintains a single, narrowly scoped HTML-to-Markdown conversion library that may be embedded in documentation workflows and content-processing pipelines. Its observed vulnerability surface centers on access-control and dependency-trust issues, including improper file and directory exposure and inclusion of functionality from untrusted sources, which are relevant to any tool that processes external input or manages sensitive file paths. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Markdownify Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41709HIGH Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is pos | Oct 19, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-41710MEDIUM Markdownify version 1.4.1 allows an external attacker to remotely obtain arbitrary local files on any client that attempts to view a malicious markdown file through Markdownify. Th | Nov 3, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Markdownify Project.
Media articles that mention a CVE ID that affects a product developed by Markdownify Project — matched by CVE ID, not by vendor name.