gitlab.freedesktop.org
https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205 CVE-2022-4055
HIGH
Record summary
CVE-2022-4055 has a selected CVSS score of 7.4 (high).
Description
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 29, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
xdg-utils | CVE List | xdg-utils 1.1.0 to and including 1.1.3 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-4055