Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cch3-2vm3-v73j

Опубликовано: 20 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.1

Описание

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

EPSS

Процентиль: 1%
0.00011
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 4.1
ubuntu
2 месяца назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVSS3: 4.1
nvd
2 месяца назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).

CVSS3: 4.1
debian
2 месяца назад

open_actions.py in kitty before 0.41.0 does not ask for user confirmat ...

EPSS

Процентиль: 1%
0.00011
Низкий

4.1 Medium

CVSS3

Дефекты

CWE-346