fix(deps): update dependency gatsby-plugin-mdx to v2 [security] - #195
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency gatsby-plugin-mdx to v2 [security]#195renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
June 27, 2022 03:38
447c81d to
cb9910b
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
July 25, 2022 04:49
cb9910b to
5723ca7
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
August 13, 2025 14:11
6ec66bd to
ba3f831
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
August 19, 2025 14:35
ba3f831 to
c426310
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
August 31, 2025 14:24
c426310 to
6487d88
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
September 25, 2025 18:33
6487d88 to
bb06f6d
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
October 21, 2025 09:15
bb06f6d to
0d3661a
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
November 10, 2025 18:59
0d3661a to
e5df7fd
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
November 18, 2025 13:02
e5df7fd to
c027d06
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
December 3, 2025 17:27
c027d06 to
5163f86
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
December 31, 2025 16:53
5163f86 to
5e16818
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
January 8, 2026 18:01
5e16818 to
10a0cf5
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
January 19, 2026 18:34
10a0cf5 to
324b028
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
February 2, 2026 14:55
324b028 to
3f054ea
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
February 17, 2026 17:12
8c08c8b to
601ac03
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
March 5, 2026 17:47
601ac03 to
89e90fa
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
March 13, 2026 18:39
89e90fa to
7bd2851
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
3 times, most recently
from
April 1, 2026 16:42
8b5ed62 to
325c1c3
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
April 8, 2026 18:06
325c1c3 to
d30a08e
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
April 29, 2026 09:51
d30a08e to
b0063d4
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
May 18, 2026 15:11
b125a77 to
24230d8
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
June 1, 2026 23:13
b37d97a to
8ea6196
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
June 11, 2026 16:53
8ea6196 to
0b468a9
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
July 16, 2026 20:48
f4c309e to
fe84e30
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
July 24, 2026 15:39
4af5f50 to
c677c31
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
July 30, 2026 15:34
c677c31 to
0a5ed7a
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
2 times, most recently
from
August 14, 2026 19:01
6ccb0fa to
0a907f9
Compare
renovate
Bot
force-pushed
the
renovate/npm-gatsby-plugin-mdx-vulnerability
branch
from
August 26, 2026 19:59
0a907f9 to
f27ceee
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.10.1→^2.0.0Unsanitized JavaScript code injection possible in gatsby-plugin-mdx
CVE-2022-25863 / GHSA-mj46-r4gr-5x83
More information
Details
Impact
The gatsby-plugin-mdx plugin prior to versions 3.15.2 and 2.14.1 passes input through to the
gray-matternpm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized. The vulnerability is present when passing input in both webpack (MDX files insrc/pagesor MDX file imported as component in frontend / React code) and data mode (querying MDX nodes via GraphQL). Injected JavaScript executes in the context of the build server.To exploit this vulnerability untrusted/unsanitized input would need to be sourced or added into an MDX file. The following MDX payload demonstrates a vulnerable configuration:
Patches
A patch has been introduced in
gatsby-plugin-mdx@3.15.2andgatsby-plugin-mdx@2.14.1which mitigates the issue by disabling thegray-matterJavaScript Frontmatter engine. The patch introduces a new option,JSFrontmatterEnginewhich is set tofalseby default. When settingJSFrontmatterEnginetotrue, input passed togatsby-plugin-mdxmust be sanitized before processing to avoid a security risk. Warnings are displayed when enablingJSFrontmatterEnginetotrueor if it appears that the MDX input is attempting to use the Frontmatter engine.Workarounds
If an older version of
gatsby-plugin-mdxmust be used, input passed into the plugin should be sanitized ahead of processing.We encourage projects to upgrade to the latest major release branch for all Gatsby plugins to ensure the latest security updates and bug fixes are received in a timely manner.
Credits
We would like to thank Snyk [snyk.io] for initially bringing the issue to our attention, as well as Feng Xiao and Zhongfu Su, who reported the issue to Snyk.
For more information
Email us at security@gatsbyjs.com.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
gatsbyjs/gatsby (gatsby-plugin-mdx)
v2.14.1Compare Source
v2.14.0Compare Source
🧾 Release notes
Bug Fixes
Chores
@babel/runtimedependencies #32954 (401b358)v2.13.0Compare Source
🧾 Release notes
Chores
v2.12.0Compare Source
🧾 Release notes
Chores
v2.11.0Compare Source
🧾 Release notes
Bug Fixes
2.10.1 (2021-07-26)
Bug Fixes
v2.10.1Compare Source
🧾 Release notes
Bug Fixes
2.10.1 (2021-07-26)
Bug Fixes
v2.10.0Compare Source
🧾 Release notes
Chores
v2.9.0Compare Source
🧾 Release notes
Features
Chores
v2.8.0Compare Source
🧾 Release notes
Chores
2.7.1 (2021-06-10)
Chores
v2.7.1Compare Source
🧾 Release notes
Chores
2.7.1 (2021-06-10)
Chores
v2.7.0Compare Source
🧾 Release notes
Chores
v2.6.0Compare Source
🧾 Release notes
Bug Fixes
2.5.1 (2021-05-19)
Bug Fixes
v2.5.1Compare Source
🧾 Release notes
Bug Fixes
2.5.1 (2021-05-19)
Bug Fixes
v2.5.0Compare Source
🧾 Release notes
Bug Fixes
v2.4.0Compare Source
🧾 Release notes
Bug Fixes
Chores
v2.3.0Compare Source
🧾 Release notes
Bug Fixes
v2.2.0Compare Source
🧾 Release notes
Bug Fixes
v2.1.0Compare Source
🧾 Release notes
Bug Fixes
Chores
2.0.1 (2021-03-11)
Bug Fixes
v2.0.1Compare Source
🧾 Release notes
Bug Fixes
Chores
2.0.1 (2021-03-11)
Bug Fixes
v2.0.0Compare Source
🧾 Release notes
Bug Fixes
Other Changes
1.10.1 (2021-02-24)
Note: Version bump only for package gatsby-plugin-mdx
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.