CVE-2022-25863

Executive Summary

CVE-2022-25863 exposes gatsby-plugin-mdx (v <2.14.1 and 3.0.0–3.15.2) to deserialization of untrusted data via the gray‑matter package. Attackers can inject malicious content through MDX files in webpack or via GraphQL queries, potentially leading to code execution or data tampering. Mitigation requires sanitizing all input before it reaches the plugin or upgrading to a patched version. The vulnerability is not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2022-06-10T20:15:08.227 - Last Modified: 2026-09-29T15:50:31.907

Original Description: The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this vulnerability is possible when passing input in both webpack (MDX files in src/pages or MDX file imported as a component in frontend / React code) and data mode (querying MDX nodes via GraphQL). Workaround: If an older version of gatsby-plugin-mdx must be used, input passed into the plugin should be sanitized ahead of processing.

"The conditions of conquest are always easy. We have but to toil awhile, endure awhile, believe always, and never turn back."

— Seneca
Source: NVD