CVE-2023-2318: Marktext
Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.
DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a malicious webpage and paste it into MarkText.
Affected products
- Marktext Marktext: up to and including 0.17.1
Published 2023-08-19. Last modified 2026-06-17.