vendor:
Yank Note
by:
8bitsec
8.8
CVSS
HIGH
Arbitrary Code Execution
94
CWE
Product Name: Yank Note
Affected Version From: 3.52.1
Affected Version To: 3.52.1
Patch Exists: NO
Related CWE: CVE-2023-31874
CPE: a:yank-note_project:yank_note:3.52.1
Platforms Tested: Ubuntu 22.04, Mac OS 13
2023
Yank Note v3.52.1 (Electron) – Arbitrary Code Execution
A vulnerability was discovered on Yank Note v3.52.1 allowing a user to execute arbitrary code by opening a specially crafted file.
Mitigation:
The vendor has not released a patch or mitigation for this vulnerability at the time of writing. Users are advised to refrain from opening untrusted markdown files in Yank Note.