vulnti.work

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

Info
CVECVE-2026-79079
First seen2026-09-22 07:16 UTC
Disclosed2026-09-21 22:16 UTC
Last updated2026-09-22 07:16 UTC
Channel statusauto

Summary

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

In-depth triage

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD