CVE-2025-49466
MEDIUMaerc <93bec0d - Path Traversal
Title source: llmDescription
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,
Scores
CVSS v3
5.8
EPSS
0.0048
EPSS Percentile
64.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Classification
CWE
CWE-23
Status
draft
Timeline
Published
Jun 05, 2025
Tracked Since
Feb 18, 2026