CVE-2024-14010

CRITICAL

Typora 1.7.4 - Command Injection

Title source: llm

Description

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

Exploits (1)

exploitdb WRITEUP
by Ahmet Ümit BAYRAM · localwindows
https://www.exploit-db.com/exploits/51752

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 69.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (2)
None/Typora 1.7.4
Unknown/Typora 1.7.4
Published Dec 12, 2025
Tracked Since Feb 18, 2026