Vulnerability Description
Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Twinkletray | Twinkle Tray | <= 1.13.3 |
References
- https://github.com/xanderfrangos/twinkle-tray/issues/142ExploitThird Party Advisory
- https://github.com/xanderfrangos/twinkle-tray/issues/142ExploitThird Party Advisory
FAQ
What is CVE-2021-28119?
CVE-2021-28119 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the ...
How severe is CVE-2021-28119?
CVE-2021-28119 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-28119?
Check the references section above for vendor advisories and patch information. Affected products include: Twinkletray Twinkle Tray.