Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mfwj-mqj2-x963

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 9.8

Описание

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

EPSS

Процентиль: 69%
0.00591
Низкий

8.5 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

EPSS

Процентиль: 69%
0.00591
Низкий

8.5 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78