Vulnerabilities > Gitnoteapp

DATE CVE VULNERABILITY TITLE RISK
2019-03-14 CVE-2019-9785 OS Command Injection vulnerability in Gitnoteapp Gitnote 3.1.0
gitnote 3.1.0 allows remote attackers to execute arbitrary code via a crafted Markdown file, as demonstrated by a javascript:window.parent.top.require('child_process').execFile substring in the onerror attribute of an IMG element.
local
low complexity
gitnoteapp CWE-78
7.8