CVE-2026-82805 | Typora up to 1.13.8/1.14.6 Mermaid Rendering Engine classDef/style cross site scripting

SecurityVulns

A vulnerability, which was classified as problematic, was found in Typora up to 1.13.8/1.14.6. This vulnerability affects unknown code of the component Mermaid Rendering Engine. The manipulation of the argument classDef/style results in cross site scripting.

This vulnerability is cataloged as CVE-2026-82805. The attack may be launched remotely. Furthermore, there is an exploit available.

You should upgrade the affected component.

The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.VulDB Recent EntriesRead More