Arbitrary Code Execution Vulnerability in Typora by Typora Team
CVE-2019-12172

7.8HIGH

Key Information:

Vendor

Typora

Status
Vendor
CVE Published:
17 May 2019

What is CVE-2019-12172?

Typora version 0.9.9.21.1 is vulnerable to arbitrary code execution due to a flaw in how it handles modified file URL syntax within the HREF attribute of an AREA element. Attackers can exploit this vulnerability by crafting specific file URLs, potentially leading to unauthorized code execution on macOS, Linux, or Windows systems. Users must be cautious when using the application and should apply any available patches or updates to mitigate this risk.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.