Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution. | |
| Title | Typora 1.7.4 OS Command Injection via Export PDF Preferences | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-12T19:56:12.077Z
Reserved: 2025-10-22T21:37:48.606Z
Link: CVE-2024-14010
No data.
Status : Received
Published: 2025-12-12T20:15:38.520
Modified: 2025-12-12T20:15:38.520
Link: CVE-2024-14010
No data.
OpenCVE Enrichment
No data.
Weaknesses