Medium severity6.1NVD Advisory· Published Dec 23, 2022· Updated Jun 17, 2026
CVE-2022-40011
CVE-2022-40011
Description
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- gist.github.com/wangking1/61bdd1967367301a950ffbb3d10386f3nvdExploitThird Party Advisory
- typora.comnvdNot Applicable
- wwwtyporaio.comnvdBroken Link
- typora.io/releases/allnvdRelease Notes
News mentions
0No linked articles in our index yet.