Description
nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state.




Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
Published: 2026-08-19
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The nnn text‑based file manager contains an out‑of‑bounds write bug triggered when deserializing session files that the application loads with the -s flag. A crafted session file can cause nnn to write beyond the end of a fixed‑size global buffer, corrupting adjacent memory structures. The vulnerability only affects the integrity of the running process and can lead to a crash or unpredictable behaviour, but there is no evidence of code‑execution or information‑exposure from the description.

Affected Systems

The affected product is the nnn application, specifically version 5.2, which has been confirmed vulnerable by internal testing. No explicit vulnerable‑version range was provided by the maintainer, so it is unknown whether earlier or later releases are affected. The maintainer has been notified and is working on a fix; a non‑vulnerable release has not yet been identified.

Risk and Exploitability

The flaw requires an attacker to supply a malicious session file to the nnn session directory, meaning local access or control over file placement is necessary. The EPSS score of < 1% indicates a very low probability of exploitation, aligning with the low CVSS score of 2.4. The vulnerability is not present in the CISA KEV list. Overall, the risk is modest. Proper file‑system permissions or disabling the -s option can mitigate the attack surface, and applying an official patch or upgrade once available is the most effective defense.

Generated by OpenCVE AI on August 20, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official patch or upgrade to a non‑vulnerable nnn release as soon as it becomes available
  • Configure the nnn session directory with restrictive permissions (e.g., 700) so that only trusted users can write session files
  • Disable or tightly control thes option, or change configuration so that untrusted session files are not loaded by nnn

Generated by OpenCVE AI on August 20, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Nnn
Nnn nnn
Vendors & Products Nnn
Nnn nnn

Wed, 19 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file can cause nnn to write data beyond the bounds of fixed-size global buffers when loaded with the -s option. An attacker who can place a malicious session file in the victim's nnn session directory can exploit this to corrupt adjacent global state. Maintainer of this project was notified about this vulnerability. It might has been addressed, but the maintainer did not provide a vulnerable version range. Only version 5.2 was tested and confirmed as vulnerable.
Title Out-of-bounds write in nnn
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-08-20T15:57:12.146Z

Reserved: 2026-07-22T10:59:31.846Z

Link: CVE-2026-65609

cve-icon Vulnrichment

Updated: 2026-08-20T15:53:47.956Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T14:17:38.060

Modified: 2026-08-28T15:26:19.533

Link: CVE-2026-65609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:30:03Z

Weaknesses