PT-2026-55775 · Unknown · Tidgi-Desktop
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
tiddly-gittly TidGi-Desktop versions prior to 0.13.1
Description
A remote code injection issue exists within the Git Repository Import component. The flaw is located in the
src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts file, where an unknown function fails to properly handle input, allowing an attacker to execute arbitrary code.Recommendations
Update tiddly-gittly TidGi-Desktop to a version newer than 0.13.0.
Restrict the use of the Git Repository Import component until the update is applied.
Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tidgi-Desktop