CVE-2023-2316: Typora Local File Disclosure
Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>".
This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2316?
CVE-2023-2316 is a vulnerability in Typora before version 1.6.7 on Windows and Linux that allows a crafted webpage to access local files and exfiltrate them to remote web servers.
How does the vulnerability in Typora work?
The vulnerability in Typora allows a malicious markdown file or copied text to access local files and send them to remote web servers via 'typora://app/<absolute-path>'.
How can the Typora vulnerability be exploited?
The Typora vulnerability can be exploited by tricking a user into opening a malicious markdown file or copying text that triggers the vulnerability.
What is the severity of CVE-2023-2316?
CVE-2023-2316 has a severity value of 7.4, which is considered high.
How can I fix the Typora vulnerability?
To fix the Typora vulnerability, users should update to version 1.6.7 or later of Typora.