Loading HuntDB...

GHSA-hg6x-mmgv-6qvx

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.

Related CVEs

Key Information

GHSA ID
GHSA-hg6x-mmgv-6qvx
Published
May 14, 2022 3:10 AM
Last Modified
May 14, 2022 3:10 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 16, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.