PT-2022-26996 · Typora · Typora

Eiji Mori

·

Published

2022-12-07

·

Updated

2025-04-23

·

CVE-2022-43668

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Typora versions prior to 1.4.4
Description The issue is related to the improper neutralization of JavaScript code. When a file is opened with the affected product, it may result in the execution of JavaScript code contained in the file.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider avoiding the opening of files that may contain JavaScript code until the update is applied.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-43668

Affected Products

Typora