Skip to content

chore(deps): update dependency kramdown to v2 [security]#270

Open
renovate-bot wants to merge 1 commit into
googleapis:mainfrom
renovate-bot:renovate/rubygems-kramdown-vulnerability
Open

chore(deps): update dependency kramdown to v2 [security]#270
renovate-bot wants to merge 1 commit into
googleapis:mainfrom
renovate-bot:renovate/rubygems-kramdown-vulnerability

Conversation

@renovate-bot
Copy link
Copy Markdown
Contributor

@renovate-bot renovate-bot commented Mar 30, 2026

This PR contains the following updates:

Package Change Age Confidence
kramdown (source) "~> 1.5""~> 2.3" age confidence

Unintended read access in kramdown gem

CVE-2020-14001 / GHSA-mqm2-cgpr-p4m6

More information

Details

The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot renovate-bot requested a review from a team as a code owner March 30, 2026 21:01
@trusted-contributions-gcf trusted-contributions-gcf Bot added the kokoro:force-run Add this label to force Kokoro to re-run the tests. label Mar 30, 2026
@renovate-bot renovate-bot force-pushed the renovate/rubygems-kramdown-vulnerability branch 3 times, most recently from c0f6ebf to 8285c55 Compare April 15, 2026 10:02
@renovate-bot renovate-bot force-pushed the renovate/rubygems-kramdown-vulnerability branch 5 times, most recently from 6f76c8a to 799451f Compare April 23, 2026 16:15
@renovate-bot renovate-bot force-pushed the renovate/rubygems-kramdown-vulnerability branch 4 times, most recently from 5234782 to 683cc65 Compare April 30, 2026 18:58
@renovate-bot renovate-bot force-pushed the renovate/rubygems-kramdown-vulnerability branch 6 times, most recently from 0eb58cc to 3d8dfca Compare May 18, 2026 17:03
@renovate-bot renovate-bot force-pushed the renovate/rubygems-kramdown-vulnerability branch 3 times, most recently from 48d6e8d to 9f25c08 Compare May 28, 2026 18:50
@renovate-bot renovate-bot force-pushed the renovate/rubygems-kramdown-vulnerability branch from 9f25c08 to 9de2ea7 Compare May 28, 2026 23:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

kokoro:force-run Add this label to force Kokoro to re-run the tests.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant