PT-2025-50970 · Typora · Typora

Published

2025-12-12

·

Updated

2025-12-15

·

CVE-2024-14010

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Typora version 1.7.4
Description Typora version 1.7.4 has a command injection issue in the PDF export preferences. This allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export, leading to remote code execution. The run command input field is the point of exploitation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-14010

Affected Products

Typora