Impact
A vulnerability in Typora’s Mermaid rendering engine allows an unauthenticated attacker to craft malicious classDef/style arguments that are evaluated as JavaScript, leading to arbitrary script execution in the user’s environment. The flaw is a classic cross‑site scripting vulnerability, formally identified as CWE-79, and it also involves code execution within the host process, matching CWE-94. An affected user can trigger the payload by opening a specially crafted file or document containing the malicious Mermaid notation, thereby compromising confidentiality, integrity, and availability of their data.
Affected Systems
Typora Desktop Editor versions up to 1.13.8 and 1.14.6 are affected. The vendor is Typora, and the known vulnerable component is the Mermaid rendering engine embedded in the editor. Users running any of these releases on Windows, macOS, or Linux are at risk unless the application is updated.
Risk and Exploitability
The CVSS vector indicates a moderate severity of 5.3. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The flaw can be exploited remotely via a malicious file or document, and the exploit has already been made public. Although the attack surface is limited to compromised or untrusted files, compromised users may execute arbitrary scripts in the context of the editor, potentially leading to the disclosure or manipulation of local documents and system resources.
OpenCVE Enrichment