AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2019-12172

HIGH · CVSS 7.8 EPSS 1.81% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-05-17 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Windows, Linux. Public exploit code or proof-of-concept references have been detected in its references.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-12172
Severity
HIGH
CVSS
7.8
EPSS
1.81%
Windows Linux

Original NVD Description

Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by file:\\\ on macOS or Linux, or file://C| on Windows. This is different from CVE-2019-12137.

Related CVEs

Other vulnerabilities affecting the same vendor(s)