CVE-2022-4055 is a high-severity vulnerability affecting freedesktop xdg_utils when xdg-mail is configured with Thunderbird. Improper parsing of mailto URLs allows an attacker to craft malicious links that appear safe but can lead to unintended file attachments when clicked. The vulnerability has a CVSS score of 7.4, indicating a high impact on integrity with no confidentiality or availability impact, and requires user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.0, <= 1.1.3CPE matchmatch criteria | cpe:2.3:a:freedesktop:xdg-utils:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
Nov 8, 2022xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments
Aug 3, 2022