CVE-2025-66400 - CVE House
Back to Database
Status published Medium CVE-2025-66400

mdast-util-to-hast unsanitized class attribute

Vulnerability Description

mdast-util-to-hast is an mdast utility to transform to hast. From 13.0.0 to before 13.2.1, multiple (unprefixed) classnames could be added in markdown source by using character references. This could make rendered user supplied markdown code elements appear like the rest of the page. This vulnerability is fixed in 13.2.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66400

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

syntax-tree

View all reports →

Affected Software

mdast-util-to-hast
Vulnerable Versions:
>= 13.0.0, < 13.2.1

Timeline

Official Publish: December 1st, 2025
Last Modified: December 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)