← Back

Kramdown Project

kramdown_project

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Kramdown
kramdown

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectKramdown Project
3Debian Linux
FedoraKramdown
Jun 17, 2026
Mar 19, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraKramdown+1 more
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (...Show more
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.Show less