PT-2026-83883 · Typora · Typora
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Typora versions 1.13.8 and 1.14.6
Description
A cross site scripting issue exists within the Mermaid Rendering Engine component. A remote attacker can trigger this by manipulating the
classDef or style arguments. Cross site scripting is a technique where malicious scripts are injected into trusted websites or applications.Recommendations
Upgrade to version 1.14.8.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Typora