Freedom maintains a small portfolio of security and document-handling tools including Dangerzone, SecureDrop, and SecureDrop Client, which are designed for sensitive file processing and secure communication workflows. Vulnerabilities affecting this vendor recur around file-path and input-handling weaknesses, including absolute path traversal, external control of file names or paths, improper link resolution, and escape-sequence neutralization issues that are characteristic of applications managing untrusted or sensitive file inputs. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freedom over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4563HIGH A vulnerability was found in Freedom of the Press SecureDrop. It has been rated as critical. Affected by this issue is some unknown functionality of the file gpg-agent.conf. The ma | Dec 16, 2022 | 7.8 | 26 | NO | NO |
CVE-2026-35465HIGH SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compro | Apr 18, 2026 | 7.5 | 25 | NO | NO |
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the conta | Aug 8, 2023 | 3.6 | 13 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freedom.
Media articles that mention a CVE ID that affects a product developed by Freedom — matched by CVE ID, not by vendor name.