CVE-2019-6803: Typora

Medium severity, CVSS 6.1. EPSS: 1.9% chance of exploitation in the next 30 days.

typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.

Affected products

  • Typora Typora: version 0.8.1 only; version 0.8.2 only; version 0.8.5 only; version 0.8.6 only; version 0.8.7 only; version 0.8.8 only; …

Published 2019-01-25. Last modified 2026-06-17.