Mark Text up to and including 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
marktext marktext |