Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-41709: GitHub - amitmerchant1990/electron-markdownify: A minimal Markdown editor desktop app

Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Markdownify. This is possible because the application has the “nodeIntegration” option enabled.

CVE
#web#mac#windows#linux#nodejs#js#git#pdf

**

Markdownify
****A minimal Markdown Editor desktop app built on top of Electron.**

Key Features • How To Use • Download • Credits • Related • License

Key Features

  • LivePreview - Make changes, See changes
    • Instantly see what your Markdown documents look like in HTML as you create them.
  • Sync Scrolling
    • While you type, LivePreview will automatically scroll to the current location you’re editing.
  • GitHub Flavored Markdown
  • Syntax highlighting
  • KaTeX Support
  • Dark/Light mode
  • Toolbar for basic Markdown formatting
  • Supports multiple cursors
  • Save the Markdown preview as PDF
  • Emoji support in preview 🎉
  • App will keep alive in tray for quick usage
  • Full screen mode
    • Write distraction free.
  • Cross platform
    • Windows, macOS and Linux ready.

How To Use

To clone and run this application, you’ll need Git and Node.js (which comes with npm) installed on your computer. From your command line:

Clone this repository

$ git clone https://github.com/amitmerchant1990/electron-markdownify

Go into the repository

$ cd electron-markdownify

Install dependencies

$ npm install

Run the app

$ npm start

Note If you’re using Linux Bash for Windows, see this guide or use node from the command prompt.

Download

You can download the latest installable version of Markdownify for Windows, macOS and Linux.

Emailware

Markdownify is an emailware. Meaning, if you liked using this app or it has helped you in any way, I’d like you send me an email at [email protected] about anything you’d want to say about this software. I’d really appreciate it!

Credits

This software uses the following open source packages:

  • Electron
  • Node.js
  • Marked - a markdown parser
  • showdown
  • CodeMirror
  • Emojis are taken from here
  • highlight.js

Related

markdownify-web - Web version of Markdownify

Support

Or

You may also like…

  • Pomolectron - A pomodoro app
  • Correo - A menubar/taskbar Gmail App for Windows and macOS

License

MIT

amitmerchant.com · GitHub @amitmerchant1990 · Twitter @amit_merchant

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907