Activitywatch is a time-tracking and productivity-monitoring application whose vulnerability profile centers on authentication and command-injection flaws in its core product. The observed weakness classes—authentication bypass by spoofing and OS command injection—reflect the input-handling and access-control demands of a locally executed monitoring tool; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activitywatch over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32692CRITICAL Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch ru | Dec 23, 2022 | 9.6 | 30 | NO | NO |
CVE-2022-31149CRITICAL ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. This vulnerability impacts everyone running ActivityWatch and | Sep 7, 2022 | 9.6 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activitywatch.
Media articles that mention a CVE ID that affects a product developed by Activitywatch — matched by CVE ID, not by vendor name.