Codigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown File
Vulnerability Description
Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell commands through Node.js child_process module when the file is opened.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-53940
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- 8bitsec
Affected Vendor
Alfonzm
View all reports →