VulnerabilityModified
CVE-2023-40580
It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet is unlocked.
MEDIUM 6.5EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet is unlocked. This vulnerability impacts access control to the mnemonic recovery phrase. This issue was patched in version 5.3.1.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- stellar/freighter
- Source
- security-advisories@github.com
References
- https://github.com/stellar/freighter/commit/81f78ba008c41ce631a3d0f9e4449f4bbd90baeePatch
- https://github.com/stellar/freighter/pull/948Patch
- https://github.com/stellar/freighter/security/advisories/GHSA-vqr6-hwg2-775wPatch, Third Party Advisory
- https://github.com/stellar/freighter/commit/81f78ba008c41ce631a3d0f9e4449f4bbd90baeePatch
- https://github.com/stellar/freighter/pull/948Patch
- https://github.com/stellar/freighter/security/advisories/GHSA-vqr6-hwg2-775wPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.