VendorsMacDown Projectmacdownall versions
Vulnerabilities

MacDown Project MacDown

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-12173
MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element. This is different from CVE-2019-12138.
Published 2019-05-17 · Modified
8.8EPSS 0.038
CVE-2019-12138
MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
Published 2019-05-16 · Modified
7.8EPSS 0.009