CVE-2019-12137: Path Traversal
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-12137?
CVE-2019-12137 is a vulnerability in Typora 0.9.9.24.6 on macOS that allows directory traversal for execution of arbitrary programs.
How does CVE-2019-12137 work?
CVE-2019-12137 works by exploiting a directory traversal vulnerability, which allows an attacker to navigate through the file system and execute arbitrary programs.
Is my version of Typora affected by CVE-2019-12137?
Yes, if you are using Typora 0.9.9.24.6 on macOS, your version is affected by CVE-2019-12137.
How can I fix CVE-2019-12137?
To fix CVE-2019-12137, you should update to a version of Typora that has addressed the directory traversal vulnerability.
Where can I find more information about CVE-2019-12137?
You can find more information about CVE-2019-12137 on the following references: [Link1](http://packetstormsecurity.com/files/153082/Typora-0.9.9.24.6-Directory-Traversal.html), [Link2](https://github.com/typora/typora-issues/issues/2505), [Link3](https://twitter.com/RandomDhiraj/status/1136960564540915712).