[High] CVE-2026-50733 – Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating u...
High CVE-2026-50733 Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled...