Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cch3-2vm3-v73j

Опубликовано: 20 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

EPSS

Процентиль: 6%
0.00025
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 4.1
ubuntu
10 месяцев назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVSS3: 4.1
nvd
10 месяцев назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVSS3: 4.1
debian
10 месяцев назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmat ...

CVSS3: 4.1
fstec
11 месяцев назад

Уязвимость файла open_actions.py эмулятора терминала на базе GPU KiTTY, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 6%
0.00025
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-346