Command Execution Vulnerability in Super Productivity Todo List App by Super Productivity
CVE-2026-71551

7.8HIGH

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-71551?

The Super Productivity app contains a command execution vulnerability that arises from the EXEC IPC handler's ability to accept command strings for execution without adequate permissions. Prior to version 18.13.0, this handler could be exploited via renderer code, including community plugins, enabling commands to execute with elevated privileges. A confirmation dialog is shown only on the first execution, and the default settings allow commands to be silently executed later on. This could lead to unauthorized actions if an attacker gains access to the execution channel.

Affected Version(s)

super-productivity < 18.13.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.