Typora for Windows and Linux contained local file disclosure vulnerabilities that allowed crafted Markdown content to read arbitrary files from a victim system and send them to a remote server. The first flaw, tracked as CVE-2023-2316, affected versions before 1.6.7 and was caused by improper path handling in Typora’s custom Electron protocol handler for typora://app/. An attacker could trigger the issue if a user opened a malicious Markdown file in Typora or pasted attacker-controlled content from a malicious webpage, exposing files such as C:\Windows\win.ini or /etc/passwd.
A second flaw, CVE-2023-2971, was later identified as a patch bypass and incomplete fix for the earlier issue. It affected versions before 1.7.0-dev and abused improper path handling in typora://app/typemark/ to perform path traversal and disclose local files despite Typora’s earlier restriction to paths beginning with typemark. STAR Labs SG researcher Li Jiantao reported both issues, and Typora issued fixes in 1.6.7 and 1.7.0-dev, respectively.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
STAR Labs published advisories for CVE-2023-2316 and CVE-2023-2971, detailing the original Typora local file disclosure flaw and the later patch bypass. The disclosures included exploitation conditions, affected versions, and proof-of-concept examples showing access to files such as win.ini and /etc/passwd.
Typora fixed CVE-2023-2971 in version 1.7.0-dev after STAR Labs reported the incomplete fix bypass. The patch addressed continued arbitrary local file disclosure risks on Windows and Linux.
STAR Labs researcher Li Jiantao disclosed CVE-2023-2971 to Typora, identifying a path traversal issue in typora://app/typemark/ that bypassed the earlier fix for CVE-2023-2316. The bug could let malicious markdown content read and exfiltrate arbitrary local files if opened or pasted into Typora.
Typora patched CVE-2023-2316, a local file disclosure vulnerability affecting Windows and Linux, in version 1.6.7. The flaw allowed crafted markdown content rendered in Typora to read arbitrary local files via improper path handling in the custom Electron protocol handler.
Typora introduced a mitigation for the original local file disclosure issue in version 1.6.5 by restricting typora://app/ paths to those beginning with typemark. This fix was later found to be incomplete and bypassable.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.