@astrojs/markdown-remark is vulnerable to Prototype Pollution
61
Medium Risk
Nested property walks over structured markdown-related configuration could advance across prototype-shaped keys when resolving headings and related metadata. That lets hostile documents influence lookups beyond plain own-properties and corrupt intended traversal semantics. The patch rejects prototype-like segment names during those nested accesses so traversal stops before inherited or polluted properties participate.
You are affected if you are using a version that falls within the vulnerable range.
@astrojs/markdown-remark is vulnerable to Prototype Pollution in versions 0.3.1 - 7.1.0.
Upgrade the @astrojs/markdown-remark library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant