The XMonad.Hooks.DynamicLog module in xmonad-contrib before
0.11.2 allows remote attackers to execute arbitrary commands via a
web page title, which activates the commands when the user clicks on
the xmobar window title, as demonstrated using an action tag.
{
"repository": "https://github.com/haskell/security-advisories",
"osvs": "https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export",
"home": "https://haskell.github.io/security-advisories"
}