Macdown Project maintains Macdown, a lightweight Markdown editor for macOS that sits in a niche but developer-focused application segment. The vendor's vulnerability footprint centers on path-traversal weaknesses in file-handling logic, which can arise in editors that interact with the local filesystem during document processing. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Macdown Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12173HIGH MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element. This is different from CVE-2019-12138. | May 18, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-12138HIGH MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. | May 16, 2019 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Macdown Project.
Media articles that mention a CVE ID that affects a product developed by Macdown Project — matched by CVE ID, not by vendor name.