Vulnerabilities (CVE)

Filtered by vendor Keybase Subscribe
Filtered by product Keybase
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34426 2 Keybase, Microsoft 2 Keybase, Windows 2022-01-03 7.2 HIGH 7.8 HIGH
A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository could leverage this vulnerability to potentially execute arbitrary Windows commands on a user\'s local system.
CVE-2019-16992 1 Keybase 1 Keybase 2019-10-08 5.0 MEDIUM 7.5 HIGH
The Keybase app 2.13.2 for iOS provides potentially insufficient notice that it is employing a user's private key to sign a certain cryptocurrency attestation (that an address at keybase.io can be used for Stellar payments to the user), which might be incompatible with a user's personal position on the semantics of an attestation.
CVE-2018-18629 1 Keybase 1 Keybase 2019-02-04 7.2 HIGH 7.8 HIGH
An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.