CVE-2019-12137: Typora

High severity, CVSS 7.8. EPSS: 6.5% chance of exploitation in the next 30 days.

Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.

Affected products

  • Typora Typora: version 0.9.9.24.6 only

Published 2019-05-16. Last modified 2026-06-17.