Security Advisory
CVE-2022-40011
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victims origin.