Attachment Exposure Vulnerability in xdg-email Component of xdg-utils
CVE-2020-27748
What is CVE-2020-27748?
A vulnerability has been discovered in the xdg-email component of xdg-utils, affecting versions 1.1.0-rc1 and later. This flaw enables the addition of attachments through mailto: URIs sent to users of email clients like Thunderbird. If a user executes a link containing such a malicious URI without realizing it, an attachment could be automatically included in their email, leading to potential unintentional disclosure of sensitive information. This issue specifically resides in the xdg-email code, separate from Thunderbird's own functionalities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
xdg-utils xdg-utils-1.1.0-rc1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
