PT-2023-18871 · Typora · Typora

·

CVE-2023-2317

·

Published

2023-08-18

·

Updated

2023-08-28

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Typora versions prior to 1.6.7
Description The issue allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora's main window via loading typora://app/typemark/updater/update.html in an <embed> tag. This can be exploited if a user opens a malicious markdown file in Typora or copies text from a malicious webpage and pastes it into Typora.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the <embed> tag with typora://app/typemark/updater/update.html until a patch is applied. Additionally, users should be cautious when opening markdown files from untrusted sources or copying text from potentially malicious webpages.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-2317

Affected Products

Typora