Simple Password Store Project develops a specialized credential-management utility with a narrow product scope centered on the single password store application. The recurring vulnerability signal reflects weakness in cryptographic signature verification, a critical trust boundary for a tool designed to safeguard sensitive authentication material, and defenders should prioritize understanding the impact of any disclosed flaws on the integrity of stored credentials. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Password Store Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12356CRITICAL An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete r | Jun 15, 2018 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Password Store Project.
Media articles that mention a CVE ID that affects a product developed by Simple Password Store Project — matched by CVE ID, not by vendor name.