---
id: CVE-2024-14010
title: >-
  Typora 1.7.4 contains a command injection vulnerability in the PDF export
  preferences that allows attackers to execute arbitrary system commands
summary: >-
  Typora 1.7.4 contains a command injection vulnerability in the PDF export
  preferences that allows attackers to execute arbitrary system commands.
  Attackers can inject malicious commands into the 'run command' input field
  during PDF expor…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Typora
product: Typora
affected:
  - Typora 1.7.4
published: '2025-12-12'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:17:56.967'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-14010'
references:
  - url: 'http://www.typora.io'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51752'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/typora-os-command-injection-via-export-pdf-preferences
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.01153
epssPercentile: 0.65771
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2025-12-15T17:59:10.381657Z'
ingestedAt: '2026-09-30T18:17:24.562Z'
---

## Overview

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
