vendor:
                    Typora
                by:
                    Ahmet Ümit BAYRAM
                7.1
                        CVSS
                    HIGH
                    OS Command Injection
                    78
                        CWE
                    Product Name: Typora
                    Affected Version From:  v1.7.4
                    Affected Version To:  v1.7.4
                    Patch Exists: NO
                    Related CWE: CVE-2023-XXXX
                    CPE:  a:typora:typora:1.7.4
                    Platforms Tested:  Windows 2019 Server 64bit
                    2023
                    Typora v1.7.4 – OS Command Injection
Typora v1.7.4 is vulnerable to OS command injection. An attacker can exploit this vulnerability by entering a malicious command into the 'run command' box under Preferences > Export tab > PDF, leading to remote code execution.
Mitigation:
					To mitigate this vulnerability, users should avoid inputting untrusted commands in the 'run command' box. It is recommended to update Typora to a patched version as soon as the vendor releases a fix.