Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29281.json"
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.9.0-beta7"
}
]
}
]