The XMonad.Hooks.DynamicLog module in xmonad-contrib before
0.11.2 allows remote attackers to execute arbitrary commands via a
web page title, which activates the commands when the user clicks on
the xmobar window title, as demonstrated using an action tag.
{
"repository": "https://github.com/haskell/security-advisories",
"home": "https://github.com/haskell/security-advisories",
"osvs": "https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export"
}"https://github.com/haskell/security-advisories/blob/generated/osv-export/2023/HSEC-2023-0003.json"
"https://raw.githubusercontent.com/haskell/security-advisories/refs/heads/generated/osv-export/2023/HSEC-2023-0003.json"
"https://github.com/haskell/security-advisories/tree/main/advisories/published/2023/HSEC-2023-0003.md"