Directory Traversal Vulnerability in Typora on macOS
CVE-2019-12137

7.8HIGH

Key Information:

Vendor

Typora

Status
Vendor
CVE Published:
16 May 2019

What is CVE-2019-12137?

The vulnerability in Typora 0.9.9.24.6 for macOS allows attackers to exploit directory traversal techniques. By manipulating file paths through a file:/// or ../ substring in shared notes, an attacker can execute arbitrary programs on the system. This security issue can lead to unauthorized access and compromise the integrity of the system, making it essential for users to address this vulnerability promptly.

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.