Typst 0.14.2 is now available

We have just released Typst 0.14.2. We are publishing this patch release so shortly after 0.14.1 because a memory handling vulnerability was found in the WebAssembly runtime used for executing Typst plugins. Based on our investigation, this vulnerability would be very hard to exploit in practice, but an exploit could theoretically be feasible. For this reason, we highly recommend upgrading to Typst 0.14.2. This holds in particular for local users. In the web app, the bug is not critical as the browser offers an extra layer of protection. View the changelog for Typst 0.14.2 for more details.

Locally, upgrading works as usual: Via typst update, cargo, or the package manager of your choice locally. (Note that versions in package managers might take a bit of time to update.) In the web app, the patch is applied automatically.

9 Likes

下载不了,请教。先阅读了READ ME,关闭了阻止,然后下载,跳出提示,说是回叉继续,可是,回叉后就什么也不出现了。

@Riqing_Fan Hi! We only communicate in English on this forum. Please join the QQ group Typst非官方中文交流群 (793548390) to use Chinese.

你好!这个论坛只能用英语,可以去 Typst 非官方中文交流群(QQ 793548390)用中文问。在那边问时,最好解释下“关闭了阻止”是什么意思,以及跳出了什么提示。能截图的话更好。

2 Likes