PT-2022-16478 · Marktext · Marktext

Fxha

·

Published

2022-01-29

·

Updated

2022-02-04

·

CVE-2022-24123

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MarkText versions 0.16.3 and earlier
Description The issue arises from the lack of input sanitization in mermaid blocks before rendering, potentially leading to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.
Recommendations For MarkText versions 0.16.3 and earlier, consider disabling the rendering of mermaid blocks until a patch is available to prevent potential Remote Code Execution attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24123

Affected Products

Marktext