CVE-2019-12138: Macdown Project Macdown

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.

Affected products

Published 2019-05-16. Last modified 2026-06-17.