Directory Traversal Vulnerability in aerc by Jarry
CVE-2025-49466

5.8MEDIUM

Key Information:

Vendor

Rjarry

Status
Vendor
CVE Published:
5 June 2025

What is CVE-2025-49466?

The aerc email client before version 93bec0d is susceptible to directory traversal attacks due to improper handling of file path concatenation. This vulnerability allows an attacker to manipulate the input and access files outside the intended directory, potentially leading to unauthorized exposure of sensitive information or system files. It is essential to update to the latest version to mitigate this risk and secure your application.

Affected Version(s)

aerc 0 < 93bec0de8ed5ab3d6b1f01026fe2ef20fa154329

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49466 : Directory Traversal Vulnerability in aerc by Jarry