CVE-2023-1003

MEDIUM

Typora < 1.5.5 - Code Injection via WSH JScript Handler

Title source: llm
STIX 2.1

Description

A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.8 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221736.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.221736
Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.221736
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/typora/typora-issues/issues/5623

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 28.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-94
Status published
Products (1)
typora/typora < 1.5.5
Published Mar 07, 2023
Tracked Since Feb 18, 2026