<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Jekyll</title>
  <link>https://cvedaily.com/pages/tags/jekyll.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/jekyll.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Jekyll</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:12 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2020-14001 – The kramdown gem before 2.3.0 for Ruby processes the template option inside Kram...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14001</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14001</guid>
    <pubDate>Fri, 17 Jul 2020 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-14001</strong></p>
  <p>The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%= `). NOTE: kramdown is used in Jekyll, GitLab Pages, GitHub Pages, and Thredded Forum.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14001">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-17567 – Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-17567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-17567</guid>
    <pubDate>Fri, 28 Sep 2018 00:29:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-17567</strong></p>
  <p>Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-17567">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
