CVE-2021-34426: Arbitrary command execution in Keybase Client for Windows
A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user\'s Git repository could leverage this vulnerability to potentially execute arbitrary Windows commands on a user\'s local system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-34426?
CVE-2021-34426 is a vulnerability discovered in the Keybase Client for Windows before version 5.6.0 that allows a malicious actor with write access to a user's Git repository to execute arbitrary code.
How does CVE-2021-34426 affect Keybase Client?
CVE-2021-34426 affects Keybase Client for Windows versions prior to 5.6.0.
What is the severity of CVE-2021-34426?
CVE-2021-34426 has a severity rating of 7.8 (high).
How can the vulnerability in Keybase Client be exploited?
The vulnerability in Keybase Client can be exploited by a malicious actor with write access to a user's Git repository executing the "keybase git lfs-config" command on the command-line.
Is Microsoft Windows affected by CVE-2021-34426?
No, Microsoft Windows is not vulnerable to CVE-2021-34426.