Package impact
npm / mcp-markdownify-server
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-5276 | high | 7.4 | 7.4 | 1y ago | Markdownify MCP Server allows Server-Side Request Forgery (SSRF) via the Markdownify.get() function | |||
| CVE-2025-5273 | medium | 6.5 | 6.5 | 1y ago | Markdownify MCP Server allows attackers to read arbitrary files | |||
| CVE-2025-58358 | unknown | — | — | 9mo ago | mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool |