Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typora
Typora typora |
|
| Vendors & Products |
Typora
Typora typora |
Fri, 12 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution. | |
| Title | Typora 1.7.4 OS Command Injection via Export PDF Preferences | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-12T19:55:03.584Z
Updated: 2025-12-15T17:59:17.977Z
Reserved: 2025-10-22T21:37:48.606Z
Link: CVE-2024-14010
Updated: 2025-12-15T17:59:13.886Z
Status : Awaiting Analysis
Published: 2025-12-12T20:15:38.520
Modified: 2025-12-15T18:22:40.637
Link: CVE-2024-14010
No data.