VulnerabilityDeferred
CVE-2024-42029
xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a list of app IDs and titles via the environment.
MEDIUM 6.3EPSS 0.78%
Does this matter?
Lower severity and a low EPSS score (0.78%). Track it; it rarely justifies an emergency change on its own.
Description
xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a list of app IDs and titles via the environment.
- CVSS 3.1
- 6.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- EPSS
- 0.78% probability · 54th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Source
- cve@mitre.org
References
- https://github.com/hyprwm/xdg-desktop-portal-hyprland/commit/0bb709491baffd69f4f861802f00cf60c77cc2cd
- https://github.com/hyprwm/xdg-desktop-portal-hyprland/issues/242
- https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3
- https://github.com/hyprwm/xdg-desktop-portal-hyprland/commit/0bb709491baffd69f4f861802f00cf60c77cc2cd
- https://github.com/hyprwm/xdg-desktop-portal-hyprland/issues/242
- https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.