Vulnerabilities (CVE)

Filtered by vendor Keybase Subscribe
Filtered by product Keybase
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34422 1 Keybase 1 Keybase 2021-11-16 6.0 MEDIUM 9.0 CRITICAL
The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder. A malicious user could upload a file to a shared folder with a specially crafted file name which could allow a user to execute an application which was not intended on their host machine. If a malicious user leveraged this issue with the public folder sharing feature of the Keybase client, this could lead to remote code execution.
CVE-2019-7249 1 Keybase 1 Keybase 2020-08-24 7.5 HIGH 9.8 CRITICAL
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.