Vulnerabilidades em cryptomator
9 resultadosAnálise Vexday
Cryptomator apresenta 9 vulnerabilidades conhecidas na base do Vexday, nenhuma delas sob ataque ativo ou com severidade crítica, indicando risco baixo no curto prazo. A fraqueza dominante é CWE-346 (falha na origem de origem), padrão em validações de origem/referência. Não há publicações recentes de CVEs (últimos 90 dias), sugerindo que o ecossistema está estável.
CVE-2023-39520MEDIUMCryptomator vulnerable to Local Elevation of PrivilegesEPSS 0.3%CVE-2026-32310MEDIUMCryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC pathsEPSS 0.2%CVE-2026-32309HIGHCryptomator: Hub unlocking accepts plaintext HTTP and unvalidated endpoint schemesEPSS 0.2%CVE-2023-37907HIGHCryptomator's MSI installer allows local privilege escalationEPSS 0.2%CVE-2026-29110LOWCryptomator: Leaking of cleartext paths into log file in non-debug modeEPSS 0.1%CVE-2026-32303HIGHCryptomator: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%CVE-2026-33472MEDIUMCryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)EPSS 0.1%CVE-2026-32318HIGHCryptomator for IOS: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%CVE-2026-32317HIGHCryptomator for Android: Tampered vault configuration allows MITM attack on Hub APIEPSS 0.1%