THREAT OPS › Threat News › [GHSA] GHSA-mxm6-v9r6-r94c (high) — @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
[GHSA] GHSA-mxm6-v9r6-r94c (high) — @nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
GHSA-mxm6-v9r6-r94c Severity: high CVE: CVE-2026-63671
@nuxtjs/mdc's URL sanitizer misses SVG xlink:href and data:text/html, allowing XSS from untrusted markdown at the default configuration
## Summary
`@nuxtjs/mdc` renders untrusted markdown (including raw HTML) to a Vue component tree. Across two prior advisories it added a URL/attribute sanitizer to block dangerous links in that HTML: `valid
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-63671cve
Original source: https://github.com/advisories/GHSA-mxm6-v9r6-r94c