CVE advisoryCRITICAL
CVE-2022-25863
Gatsby Plugin MDX Untrusted Data Deserialization
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
The `gatsby-plugin-mdx` component is vulnerable to deserialization of untrusted data, allowing for potential data corruption or unexpected behavior during the build process if malicious input is provided. This could occur when processing MDX files or querying MDX data.