CVE-2025-49466

NameCVE-2025-49466
Descriptionaerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
aerc (PTS)bookworm0.14.0-1fixed
trixie0.20.0-2fixed
forky, sid0.20.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
aercsourcebookworm(not affected)
aercsource(unstable)0.20.0-2

Notes

[bookworm] - aerc <not-affected> (Vulnerable code not present)
Fixed by: https://git.sr.ht/~rjarry/aerc/commit/93bec0de8ed5ab3d6b1f01026fe2ef20fa154329
Regression fix: https://git.sr.ht/~rjarry/aerc/commit/2bbe75fe0bc87ab4c1e16c5a18c6200224391629

Search for package or bug name: Reporting problems