{"ok":true,"trend":{"id":642279,"platform":"mastodon","region":"global","key":"cve-2026-78847: gray-matter (all versions) rce via eval() in lib/engines.js parsing js front matter. cvss 9.8, no patch","title":"CVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patch","url":"https://mastodon.social/@hugovalters/117366993933691888","first_seen":"2026-10-01T19:00:37.983481Z","last_seen":"2026-10-01T19:00:37.983481Z","last_rank":12,"peak_rank":12,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.66078125,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A newly published CVE, CVE-2026-78847, describes a critical remote code execution vulnerability in the gray-matter JavaScript front-matter parser. All versions are affected: code parsing JavaScript front matter uses eval() in lib/engines.js, letting attackers run arbitrary code. The flaw carries a CVSS score of 9.8 and no patch exists yet. Security commentators urge developers to avoid processing untrusted JavaScript front matter and to update as soon as a fix is released.","why":"The vulnerability affects a widely used library with no available fix, so developers are racing to assess their exposure.","tone":"neutral","entities":["gray-matter","CVE-2026-78847"],"summarized_at":"2026-10-01T19:01:50.241315Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1650},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical unpatched flaw reported in gray-matter parser","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-01T19:00:37.983481Z","rank":12,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@hugovalters/117366993933691888","author":"hugovalters","title":null,"snippet":"CVE-2026-78847: gray-matter (all versions) RCE via eval() in lib/engines.js parsing JS front matter. CVSS 9.8, no patch yet. Avoid untrusted JS front matter, update as soon as a fix lands. https://www. valtersit.com/cve/CVE-2026-788 47/ # CVE # infosec # cybersecurity","posted_at":"2026-10-01T18:10:03.364000Z","likes":0}],"elsewhere":[],"window":"7d"}}