CVE-2024-14010: Typora 1.7.4 OS Command Injection via Export PDF Preferences
Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-14010?
CVE-2024-14010 is considered a critical command injection vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-14010?
To fix CVE-2024-14010, update Typora to the latest version that addresses this vulnerability.
What systems are affected by CVE-2024-14010?
CVE-2024-14010 specifically affects Typora version 1.7.4.
What type of attacks can be performed using CVE-2024-14010?
Attackers can leverage CVE-2024-14010 to inject malicious commands that may lead to arbitrary code execution.
Is there a workaround for CVE-2024-14010 before applying a fix?
As of now, the best workaround for CVE-2024-14010 is to refrain from using the PDF export functionality in Typora 1.7.4.