Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code execution in an unsandboxed environment.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Typora 跨站脚本漏洞
Vulnerability Description
Typora是一款编辑器。 Typora 0.9.9.31.2及之前版本(macOS)和0.9.81及之前版本(Linux)中存在跨站脚本漏洞。远程攻击者可通过Mermaid代码块利用该漏洞执行代码。
CVSS Information
N/A
Vulnerability Type
N/A