Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/
- https://starlabs.sg/advisories/23/23-2316/
No PoCs found on GitHub currently.