CVE-2022-24123 is a critical vulnerability affecting MarkText through version 0.16.3, stemming from a lack of input sanitization in mermaid blocks. This flaw allows for Remote Code Execution (RCE) through a specially crafted .md file containing a mutation Cross-Site Scripting (XSS) payload. With a CVSS score of 9.0 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and requires user interaction, but can lead to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit or ExploitDB, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.16.3CPE matchmatch criteria | cpe:2.3:a:marktext:marktext:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.6 Bluesky, 0.3 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.