THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mxm6-v9r6-r94c (high) — @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration

[GHSA] GHSA-mxm6-v9r6-r94c (high) — @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration

medgithub_advisoriesPublished 2026-09-16

GHSA-mxm6-v9r6-r94c Severity: high CVE: CVE-2026-63671

@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration

## Summary

`@nuxtjs/mdc` renders untrusted markdown (including raw HTML) to a Vue component tree. Across two prior advisories it added a URL/attribute sanitizer to block dangerous links in that HTML: `valid

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mxm6-v9r6-r94c