Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Byte16384

#29159of 53,619
8.8Total CVSS
Vulnerabilities · 1
PT-2026-47023
8.8
2026-06-05
Unknown · Markdown Preview Enhanced · CVE-2026-49492
**Name of the Vulnerable Software and Affected Versions** Markdown Preview Enhanced versions prior to 0.8.28 **Description** On Windows, the software opens external files and links from the preview through a shell without validating untrusted inputs from the markdown document. This allows for the injection of operating system commands when a crafted markdown document is previewed. The issue involves the following vulnerable attributes - diagram filename - imported file paths - `latex engine` code-chunk attribute **Recommendations** Update to version 0.8.28.