The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "9.25"
},
{
"introduced": "0"
},
{
"last_affected": "9.26"
},
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
}