Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: pantheon.epiphany

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2025-3839
8.0 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 2 months ago
Epiphany: insecure external protocol invocation in epiphany

A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior.

References

Affected products

epiphany
  • <47.5
  • <48.1

Matching in nixpkgs

Package maintainers