VYPR
Medium severity5.5NVD Advisory· Published Mar 20, 2026· Updated Jun 17, 2026

CVE-2026-32810

CVE-2026-32810

Description

Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in 0644 on files and 0755 on directories. This allows any local user on the system to read plaintext credentials stored in config.toml or referenced password_file paths. Commit f180e41061db393acf65bc99f5c5e7397586d9cb patches the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:halloy:halloy:*:*:*:*:*:*:*:*
    Range: <=2026.4
  • Squidowl/Halloyllm-fuzzy2 versions
    prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb+ 1 more
    • (no CPE)range: prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb
    • (no CPE)range: <= 2026.4

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.