Seatd Project maintains a session and seat management daemon for Wayland compositors and related display-server infrastructure, with a focused vulnerability footprint centered on the seatd product itself. The observed weakness classes—resource exposure across trust boundaries and untrusted search-path handling—reflect the privilege-elevation and access-control demands inherent to a system service managing device access and user sessions.
The number and severity of CVEs published that impact products developed by Seatd Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25643CRITICAL seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname. | Feb 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-41387HIGH seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root. | Sep 17, 2021 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seatd Project.
Media articles that mention a CVE ID that affects a product developed by Seatd Project — matched by CVE ID, not by vendor name.