CVE-2020-15692
CRITICALNim < 1.2.6 - Argument Injection via browsers.openDefaultBrowser
Title source: llmDescription
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands.
References (4)
Core 4
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/browsers.nim#L48
Release Notes, Third Party Advisory x_refsource_confirm
https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/02/04/1
Exploit, Third Party Advisory x_refsource_misc
https://consensys.net/diligence/vulnerabilities/nim-browsers-argument-injection/
Scores
CVSS v3
9.8
EPSS
0.0420
EPSS Percentile
89.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-88
Status
published
Products (1)
nim-lang/nim
< 1.2.6
Published
Aug 14, 2020
Tracked Since
Feb 18, 2026