CVE-2019-7296: Typora

Medium severity, CVSS 6.1. EPSS: 1.7% chance of exploitation in the next 30 days.

typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.

Affected products

  • Typora Typora: up to and including 0.9.64

Published 2019-01-31. Last modified 2026-06-17.