PT-2026-55775 · Unknown · Tidgi-Desktop

·

CVE-2026-14722

·

Published

2026-07-05

·

Updated

2026-07-14

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions tiddly-gittly TidGi-Desktop versions prior to 0.13.1
Description A remote code injection issue exists within the Git Repository Import component. The flaw is located in the src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts file, where an unknown function fails to properly handle input, allowing an attacker to execute arbitrary code.
Recommendations Update tiddly-gittly TidGi-Desktop to a version newer than 0.13.0. Restrict the use of the Git Repository Import component until the update is applied.

Exploit

Fix

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14722
GHSA-9HC2-HJX8-Q6PV

Affected Products

Tidgi-Desktop