CVE Database
/

CVE-2025-49466

Back to search

CVE-2025-49466

Published: Jun 5, 2025

Modified: Jun 5, 2025

PUBLISHED

CVSS v3.1

5.8

MEDIUM

Description

aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,

VendorProductVersions

rjarry

aerc

affected
0 - < 93bec0de8ed5ab3d6b1f01026fe2ef20fa154329

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Changed

Confidentiality

None

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2025-49466 | MEDIUM (5.8) - Security Vulnerability | QwikSec