VYPR
High severity7.5NVD Advisory· Published Jun 6, 2019· Updated Jun 17, 2026

CVE-2019-12761

CVE-2019-12761

Description

A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pyxdgPyPI
< 0.260.26

Affected products

13

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.