search
gray-matter
Trends
- 1Critical unpatched flaw reported in gray-matter parser●CVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patch
A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.