CVE-2022-43668: XSS
Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the file when opening a file with the affected product.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43668?
CVE-2022-43668 is a vulnerability in Typora versions prior to 1.4.4 that fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the file when opening a file with the affected product.
What is the severity of CVE-2022-43668?
The severity of CVE-2022-43668 is medium with a CVSS score of 6.1.
How does CVE-2022-43668 affect Typora?
CVE-2022-43668 affects Typora versions prior to 1.4.4.
How can I fix CVE-2022-43668?
To fix CVE-2022-43668, update Typora to version 1.4.4 or later.
Where can I find more information about CVE-2022-43668?
You can find more information about CVE-2022-43668 at the following references: [Link 1](https://jvn.jp/en/jp/JVN26044739/index.html), [Link 2](https://typora.io/releases/all).