Gajim unconditionally implements the "XEP-0146: Remote Controlling Clients" extension, which may be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions (CVE-2016-10376).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0166.json"