Description
xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single quotes are not used when sending a list of app IDs and titles via the environment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xdg
Xdg desktop Portal Hyperland |
|
| CPEs | cpe:2.3:a:xdg:desktop_portal_hyperland:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xdg
Xdg desktop Portal Hyperland |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T04:54:31.354Z
Reserved: 2024-07-27T00:00:00.000Z
Link: CVE-2024-42029
Updated: 2024-08-02T04:54:31.354Z
Status : Deferred
Published: 2024-07-27T04:15:02.760
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-42029
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')