GHSA-x3rr-c2w2-46x3
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
** DISPUTED ** boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 11, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.