Typora is a markdown editor with modest but notable prominence in the vulnerability landscape, concentrated in a single widely used product for document composition and note-taking. Its disclosures cluster around input-handling and trust-boundary weaknesses including cross-site scripting, path traversal, authentication bypass, and code injection, reflecting the challenges of rendering and processing untrusted markdown content in a desktop application with web-technology foundations. A meaningful share of vulnerabilities affecting this vendor reach critical severity, underscoring the risk when a document editor can execute or access system resources beyond its intended scope. Defenders should treat Typora updates with attention to the product's role in handling potentially adversarial documents, particularly in environments where user-supplied markdown files are processed. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typora over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12137HIGH Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. | May 16, 2019 | 7.8 | 38 | NO | YES |
CVE-2023-2317CRITICAL DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main windo | Aug 19, 2023 | 9.6 | 29 | NO | NO |
CVE-2019-20374CRITICAL A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit | Jan 9, 2020 | 9.6 | 28 | NO | NO |
CVE-2019-12172HIGH Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or | May 17, 2019 | 7.8 | 25 | NO | NO |
CVE-2023-2316HIGH Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absol | Aug 19, 2023 | 7.4 | 23 | NO | NO |
CVE-2020-18336HIGH Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting function. | Oct 10, 2023 | 7.4 | 22 | NO | NO |
CVE-2020-18748MEDIUM Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in the mathematical formula blocks. | Aug 19, 2021 | 6.1 | 22 | NO | NO |
CVE-2019-6803MEDIUM typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar. | Jan 25, 2019 | 6.1 | 22 | NO | NO |
CVE-2024-33300HIGH Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown fi | May 1, 2024 | 7.3 | 21 | NO | NO |
CVE-2020-21058MEDIUM Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax. | Jun 20, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typora.
Media articles that mention a CVE ID that affects a product developed by Typora — matched by CVE ID, not by vendor name.