VDB
Sign up
CRITICAL9.1

GHSA-r3r5-jhw6-4634

Insecure temporary file usage in SWHKD

Details

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/Simple-Wayland-HotKey-Daemon
Introduced in: 0Fixed in: 1.2.0

Upgrade Simple-Wayland-HotKey-Daemon to 1.2.0 or newer (ecosystem crates.io).

References