Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v8v-cp6r-mq7c

Опубликовано: 25 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

EPSS

Процентиль: 83%
0.02034
Низкий

7.8 High

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 3 лет назад

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

CVSS3: 7.8
nvd
больше 3 лет назад

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

CVSS3: 7.8
debian
больше 3 лет назад

In Kitty before 0.26.2, insufficient validation in the desktop notific ...

EPSS

Процентиль: 83%
0.02034
Низкий

7.8 High

CVSS3

Дефекты

CWE-116