A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the ~/.local directory. This allows the attacker to inject a malicious .desktop launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-732"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6842.json"
}{
"extracted_events": [
{
"introduced": "2.9.1"
},
{
"fixed": "9.0"
}
],
"source": "AFFECTED_FIELD"
}