VYPR
Medium severity5.5NVD Advisory· Published Feb 8, 2021· Updated Jun 17, 2026

CVE-2021-26917

CVE-2021-26917

Description

PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security mitigation may not be necessary as there is no evidence yet that these screen intercepts are actually transported away from the local host." NOTE: it is unclear whether there are any common use cases in which apinotifypath is controlled by an attacker

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:bitmessage:pybitmessage:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:bitmessage:pybitmessage:*:*:*:*:*:*:*:*range: <=0.6.3.2
    • (no CPE)range: <=0.6.3.2
  • PyBitmessage/PyBitmessagedescription

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.