Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
Sun, 14 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typora
Typora typora |
|
| Vendors & Products |
Typora
Typora typora |
Fri, 12 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution. | |
| Title | Typora 1.7.4 OS Command Injection via Export PDF Preferences | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-12T19:56:12.077Z
Reserved: 2025-10-22T21:37:48.606Z
Link: CVE-2024-14010
No data.
Status : Received
Published: 2025-12-12T20:15:38.520
Modified: 2025-12-12T20:15:38.520
Link: CVE-2024-14010
No data.
OpenCVE Enrichment
Updated: 2025-12-14T21:15:53Z