Intel

AIKIDO-2026-10814

@slidev/parser is vulnerable to Improper Input Validation

Improper Input Validation Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 14, 2026

81

High Risk

This Affects:

JS@slidev/parser
0.48.0 - 52.15.1
Fixed in 52.15.2
Are you affected? Scan for Free

TL;DR

Affected versions of slidev dynamically load theme and plugin packages from user-controlled slide frontmatter or CLI arguments without sufficient validation. An attacker able to modify presentation content can cause the application to load a malicious npm package, potentially resulting in arbitrary code execution and compromise of the developer’s environment.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@slidev/parser is vulnerable to Improper Input Validation in versions 0.48.0 - 52.15.1.

How to fix this

Upgrade the slidev library to the patch version.