{"id":"CVE-2026-79079","published":"2026-09-21T22:16:59.000","lastModified":"2026-09-22T20:00:03.713","description":"An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a","tags":[]},{"url":"https://github.com/crosswire/xiphos/pull/1314/commits/68bbe3063b601537d1e505dd1a4560d51811a9e0","tags":[]},{"url":"https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a","tags":[]}],"exploitRefs":[{"url":"https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a","tags":[]},{"url":"https://github.com/crosswire/xiphos/pull/1314/commits/68bbe3063b601537d1e505dd1a4560d51811a9e0","tags":[]},{"url":"https://gist.github.com/lggcs/c1f98ce55ced44472651b9590d9f199a","tags":[]}],"hasPoc":true,"ai":null}