Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block rendering of a mathematical formula.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18221
Reference (s):
- https://github.com/typora/typora-issues/issues/2204

