Skip to content

Conversation

@aikido-autofix
Copy link
Contributor

Upgrading mdast-util-to-hast to address vulnerabilities. Changelog indicates no breaking changes are introduced and upgrading should be safe.

1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2025-66400
MEDIUM
mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerabil...

@KevinEtchells KevinEtchells merged commit cbdefab into main Dec 18, 2025
4 of 5 checks passed
@KevinEtchells KevinEtchells deleted the fix/aikido-security-update-packages-12345721-5WLm branch December 18, 2025 10:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants