Report: Latest: CVE-2026-6842 - Nano: nano: local attacker can inject malicious .desktop launcher due to insecure...

Report: Latest: CVE-2026-6842 - Nano: nano: local attacker can inject malicious .desktop launcher due to insecure...

CVE ID :CVE-2026-6842 Published : 22 Apr 2026, 8:16 a.m. | 49 minutes ago Description :A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for the `~/.local` directory. This allows the attacker to inject a malicious `.desktop` launcher, which could lead to unintended actions or information disclosure if the launcher is subsequently processed. Severity: 2.5 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
LOW
Attack Vector: local
Impact: information disclosure