CVE-2019-12173: Macdown Project Macdown

High severity, CVSS 8.8. EPSS: 3.8% chance of exploitation in the next 30 days.

MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element. This is different from CVE-2019-12138.

Affected products

Published 2019-05-18. Last modified 2026-06-17.