← العودة للجدول
CVE-2026-49492
CVE-2026-49492 — GHSA: Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a...
📅 2026-06-05
🟠 High 🔥 No GHSA Exploit Vulnerability CVSS 8.8

📋 الوصف الكامل

Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - the diagram filename attribute, imported file paths, and the latex_engine code-chunk attribute. On Windows, a crafted markdown document can inject operating system commands that execute when the document is previewed. Fixe

💻 الأنظمة المتأثرة

Microsoft Windows

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-49492

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←