Improperly Controlled Modification of Dynamically-Determined Object Attributes Affecting mdast-util-to-hast package, versions >=13.0.0 <13.2.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-MDASTUTILTOHAST-14157221
  • published3 Dec 2025
  • disclosed1 Dec 2025
  • creditUnknown

Introduced: 1 Dec 2025

NewCVE-2025-66400  (opens in a new tab)
CWE-915  (opens in a new tab)

How to fix?

Upgrade mdast-util-to-hast to version 13.2.1 or higher.

Overview

mdast-util-to-hast is a mdast utility to transform to hast

Affected versions of this package are vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes in the class attribute in rendered markdown code elements. An attacker can cause arbitrary CSS classes to be applied to elements by injecting specially crafted character references, altering the appearance or behavior of rendered content.

CVSS Base Scores

version 4.0
version 3.1