CVE-2022-40011: XSS
Cross Site Scripting (XSS) vulnerability in typora through 1.38 allows remote attackers to run arbitrary code via export from editor.
Other sources
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-40011?
CVE-2022-40011 is a Cross Site Scripting (XSS) vulnerability in typora through version 1.38.
How does CVE-2022-40011 impact typora?
CVE-2022-40011 allows remote attackers to run arbitrary code via export from the typora editor.
What is the severity of CVE-2022-40011?
CVE-2022-40011 has a severity rating of 6.1, classified as medium.
How can I fix CVE-2022-40011?
To fix CVE-2022-40011, update typora to a version later than 1.38, as the vulnerability has been patched.
Where can I find more information about CVE-2022-40011?
You can find more information about CVE-2022-40011 on the official typora website, typora.com, and the typoraio.com website. Additionally, there is a GitHub Gist available with further details.