An issue in Typora v.1.8.10 and before, allows a local malicious user to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.