{"api_version":"1","generated_at":"2026-07-23T13:46:02+00:00","cve":"CVE-2023-1003","urls":{"html":"https://cve.report/CVE-2023-1003","api":"https://cve.report/api/cve/CVE-2023-1003.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-1003","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-1003"},"summary":{"title":"CVE-2023-1003","description":"A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.8 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221736.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-03-07 20:15:00","updated_at":"2023-11-07 04:02:00"},"problem_types":["CWE-94"],"metrics":[],"references":[{"url":"https://github.com/typora/typora-issues/issues/5623","name":"https://github.com/typora/typora-issues/issues/5623","refsource":"MISC","tags":[],"title":"Typora on Windows fails to properly filter WSH JScript, which may result in code execution · Issue #5623 · typora/typora-issues · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://vuldb.com/?id.221736","name":"https://vuldb.com/?id.221736","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://vuldb.com/?ctiid.221736","name":"https://vuldb.com/?ctiid.221736","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-1003","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1003","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"1003","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"1003","vulnerable":"1","versionEndIncluding":"1.5.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"typora","cpe5":"typora","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-1003","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.8 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221736."},{"lang":"deu","value":"Es wurde eine Schwachstelle in Typora bis 1.5.5 für Windows gefunden. Sie wurde als kritisch eingestuft. Hiervon betroffen ist ein unbekannter Codeblock der Komponente WSH JScript Handler. Durch das Beeinflussen mit unbekannten Daten kann eine code injection-Schwachstelle ausgenutzt werden. Der Angriff hat dabei lokal zu erfolgen. Der Exploit steht zur öffentlichen Verfügung. Ein Aktualisieren auf die Version 1.5.8 vermag dieses Problem zu lösen. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-94 Code Injection","cweId":"CWE-94"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Typora","version":{"version_data":[{"version_affected":"=","version_value":"1.5.0"},{"version_affected":"=","version_value":"1.5.1"},{"version_affected":"=","version_value":"1.5.2"},{"version_affected":"=","version_value":"1.5.3"},{"version_affected":"=","version_value":"1.5.4"},{"version_affected":"=","version_value":"1.5.5"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.221736","refsource":"MISC","name":"https://vuldb.com/?id.221736"},{"url":"https://vuldb.com/?ctiid.221736","refsource":"MISC","name":"https://vuldb.com/?ctiid.221736"},{"url":"https://github.com/typora/typora-issues/issues/5623","refsource":"MISC","name":"https://github.com/typora/typora-issues/issues/5623"}]},"credits":[{"lang":"en","value":"Tom23 (VulDB User)"}],"impact":{"cvss":[{"version":"3.1","baseScore":5.3,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"},{"version":"3.0","baseScore":5.3,"vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"},{"version":"2.0","baseScore":4.3,"vectorString":"AV:L/AC:L/Au:S/C:P/I:P/A:P"}]}},"nvd":{"publishedDate":"2023-03-07 20:15:00","lastModifiedDate":"2023-11-07 04:02:00","problem_types":["CWE-94"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:typora:typora:*:*:*:*:*:*:*:*","versionEndIncluding":"1.5.5","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}