PT-2023-18871 · Typora · Typora

Cursered

+1

·

Published

2023-08-18

·

Updated

2023-08-28

·

CVE-2023-2317

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Typora versions prior to 1.6.7
Description The issue allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora's main window via loading typora://app/typemark/updater/update.html in an <embed> tag. This can be exploited if a user opens a malicious markdown file in Typora or copies text from a malicious webpage and pastes it into Typora.
Recommendations For versions prior to 1.6.7, update to version 1.6.7 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the <embed> tag with typora://app/typemark/updater/update.html until a patch is applied. Additionally, users should be cautious when opening markdown files from untrusted sources or copying text from potentially malicious webpages.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-2317

Affected Products

Typora