An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for profanity (0.4.7 - 0.5.0).
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:profanity_project:profanity:0.4.7:-:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.4.7:cyg1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0.4.7-NA"
},
{
"last_affected": "0.4.7-NA"
},
{
"introduced": "0.4.7-cyg1"
},
{
"last_affected": "0.4.7-cyg1"
}
],
"vendor_product": "profanity_project:profanity"
}
]
}{
"source": [
"CPE_STRING",
"REFERENCES"
],
"cpe": [
"cpe:2.3:a:profanity_project:profanity:0.4.7:-:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.4.7:cyg1:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.4.7:patch1:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.4.7:cyg2:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.4.7:cyg3:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.5.0:-:*:*:*:*:*:*",
"cpe:2.3:a:profanity_project:profanity:0.5.0:rc1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0.4.7-NA"
},
{
"last_affected": "0.4.7-NA"
},
{
"introduced": "0.4.7-cyg1"
},
{
"last_affected": "0.4.7-cyg1"
},
{
"introduced": "0.4.7-patch1"
},
{
"last_affected": "0.4.7-patch1"
},
{
"introduced": "0.4.7-cyg2"
},
{
"last_affected": "0.4.7-cyg2"
},
{
"introduced": "0.4.7-cyg3"
},
{
"last_affected": "0.4.7-cyg3"
},
{
"introduced": "0.5.0-NA"
},
{
"last_affected": "0.5.0-NA"
},
{
"introduced": "0.5.0-rc1"
},
{
"last_affected": "0.5.0-rc1"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5592.json"
"2026-07-08T16:53:33Z"
[
{
"id": "CVE-2017-5592-605a0cf6",
"digest": {
"line_hashes": [
"43674570987415379562834289238571991228",
"85997097170914970319998696623555001435",
"199915616696410343235400945864382345600",
"67141778361390527333760574197905403924"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "tests/functionaltests/test_carbons.c"
},
"source": "https://github.com/profanity-im/profanity/commit/8e75437a7e43d4c55e861691f74892e666e29b0b",
"deprecated": false
},
{
"id": "CVE-2017-5592-838b1a83",
"digest": {
"line_hashes": [
"269672725800911013049720229985177148429",
"147937880059459280781124999408304611935",
"98013001733306130113818985562635411688",
"48435102129655158876459487600381447272",
"274643813655947615398101824109268710667",
"323088572927188402907203319880457121370",
"9590343397176827005811879247126636121"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "src/xmpp/message.c"
},
"source": "https://github.com/profanity-im/profanity/commit/8e75437a7e43d4c55e861691f74892e666e29b0b",
"deprecated": false
},
{
"id": "CVE-2017-5592-8d394e89",
"digest": {
"length": 1119.0,
"function_hash": "44724400157544853113936891218358527427"
},
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "tests/functionaltests/test_carbons.c",
"function": "receive_carbon"
},
"source": "https://github.com/profanity-im/profanity/commit/8e75437a7e43d4c55e861691f74892e666e29b0b",
"deprecated": false
}
]