Arbitrary Code Execution Vulnerability in Typora by Typora Team
CVE-2019-12172
7.8HIGH
What is CVE-2019-12172?
Typora version 0.9.9.21.1 is vulnerable to arbitrary code execution due to a flaw in how it handles modified file URL syntax within the HREF attribute of an AREA element. Attackers can exploit this vulnerability by crafting specific file URLs, potentially leading to unauthorized code execution on macOS, Linux, or Windows systems. Users must be cautious when using the application and should apply any available patches or updates to mitigate this risk.
