CVE-2026-78847
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
22/09/2026
Description
An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL


