Unifiedjs maintains a collection of JavaScript libraries for parsing and transforming markup syntax trees, with its vulnerability footprint centered on the mdast-util-to-hast module that bridges abstract syntax tree conversion. The recurrent weaknesses in this ecosystem are improper input validation and uncontrolled modification of dynamically determined object attributes, reflecting the risks inherent to tree traversal and object manipulation in parsing pipelines. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unifiedjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66400MEDIUM mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character ref | Dec 1, 2025 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unifiedjs.
Media articles that mention a CVE ID that affects a product developed by Unifiedjs — matched by CVE ID, not by vendor name.