The Umask Project maintains a narrowly scoped utility focused on file-permission management, with its vulnerability profile centered on the core umask product and the mechanics of permission assignment. The recurring weakness class involves improper handling of critical-resource permissions, reflecting the sensitivity of access-control logic in this functional domain. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Umask Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31155HIGH Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are allowed to execute at least one command. | May 27, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Umask Project.
Media articles that mention a CVE ID that affects a product developed by Umask Project — matched by CVE ID, not by vendor name.