High severity7.5NVD Advisory· Published Jun 6, 2019· Updated Jun 17, 2026
CVE-2019-12761
CVE-2019-12761
Description
A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pyxdgPyPI | < 0.26 | 0.26 |
Affected products
13- PyXDG/PyXDGdescription
- ghsa-coords11 versionspkg:pypi/pyxdgpkg:rpm/suse/python-pyxdg&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python-pyxdg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1
< 0.26+ 10 more
- (no CPE)range: < 0.26
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
- (no CPE)range: < 0.25-150000.3.3.1
Patches
Vulnerability mechanics
References
7- gist.github.com/dhondta/b45cd41f4186110a354dc7272916febanvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r6v3-hpxj-r8rvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-12761ghsaADVISORY
- snyk.io/vuln/SNYK-PYTHON-PYXDG-174562nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/pyxdg/PYSEC-2019-199.yamlghsaWEB
- lists.debian.org/debian-lts-announce/2019/06/msg00006.htmlnvdWEB
- lists.debian.org/debian-lts-announce/2021/08/msg00003.htmlnvdWEB
News mentions
0No linked articles in our index yet.