Impact
The vulnerability resides in the loadWikiTiddlersWithSubWikis module of TidGi-Desktop and permits an attacker to inject arbitrary code during the Git Repository Import routine. This code injection is described as a defect that allows source code to be improperly neutralized and generated, corresponding to CWE-74 and CWE-94. When a specially crafted repository is processed, the application may execute the injected payload with the privileges it holds, which could enable the attacker to carry out unintended actions on the host.
Affected Systems
TidGi-Desktop versions 0.13.0 and earlier are affected. Users who employ the Git Repository Import function in these releases are at risk.
Risk and Exploitability
With a CVSS score of 6.9 the flaw is considered moderate in severity, while the EPSS score of less than 1 % indicates a low probability of widespread exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and no large‑scale attacks have been reported. Exploitation can be performed remotely by submitting a malicious Git repository to the import interface, potentially resulting in the application executing arbitrary code.
OpenCVE Enrichment