An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.
                
            References
                    Configurations
                    History
                    10 Jun 2025, 01:14
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:typora:typora:*:*:*:*:*:*:*:* | |
| First Time | 
        
        Typora
         Typora typora  | 
|
| References | () https://github.com/0x0fc/TyporaIframe/blob/main/TyporaIframeVuln.md - Exploit | 
21 Nov 2024, 09:13
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://github.com/0x0fc/TyporaIframe/blob/main/TyporaIframeVuln.md - | 
01 Aug 2024, 13:51
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-290 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 6.1  | 
16 Apr 2024, 13:24
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
16 Apr 2024, 04:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-04-16 04:15
Updated : 2025-06-10 01:14
NVD link : CVE-2024-31784
Mitre link : CVE-2024-31784
CVE.ORG link : CVE-2024-31784
JSON object : View
Products Affected
                typora
- typora
 
CWE
                
                    
                        
                        CWE-290
                        
            Authentication Bypass by Spoofing
