Security Advisory
CVE-2022-40011
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a victim's origin.