MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 2 h ago, last 2 h ago, peak #12

Critical unpatched flaw reported in gray-matter parser

Original: CVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patch

A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.

Why now: The vulnerability affects a widely used library with no available fix, so developers are racing to assess their exposure.

gray-matterCVE-2026-78847

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/642279