Vulnerabilities > Macdown Project

DATE CVE VULNERABILITY TITLE RISK
2019-05-18 CVE-2019-12173 Path Traversal vulnerability in Macdown Project Macdown 0.7.1
MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A element.
6.8
2019-05-16 CVE-2019-12138 Path Traversal vulnerability in Macdown Project Macdown 0.7.1
MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.
local
low complexity
macdown-project CWE-22
4.6