Command Injection Vulnerability in Typora by Typora
CVE-2024-14010
Key Information:
Badges
What is CVE-2024-14010?
Typora version 1.7.4 is susceptible to a command injection vulnerability that arises during PDF export. This flaw allows attackers to inject malicious commands into the 'run command' input field, potentially leading to the execution of arbitrary system commands. Exploiting this vulnerability could enable an unauthorized user to execute remote code, posing serious risks to system integrity. Users are advised to update to a patched version to mitigate this risk.
Affected Version(s)
Typora 1.7.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
