Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file is opened.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 18 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Description Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file is opened.
Title Codigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown File
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-18T20:19:40.737Z

Reserved: 2025-12-16T19:22:09.997Z

Link: CVE-2023-53940

cve-icon Vulnrichment

Updated: 2025-12-18T20:19:36.556Z

cve-icon NVD

Status : Received

Published: 2025-12-18T20:15:52.470

Modified: 2025-12-18T20:15:52.470

Link: CVE-2023-53940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses