CVE-2023-1005

MEDIUM

Markdown-Electron - Code Injection

Title source: llm
STIX 2.1

Description

A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-221738 is the identifier assigned to this vulnerability.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.221738
Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.221738
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/JP1016/Markdown-Electron/issues/3

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 28.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-94
Status published
Products (1)
markdown-electron_project/markdown-electron
Published Feb 24, 2023
Tracked Since Feb 18, 2026