CVE-2026-79079: CrossWire Xiphos vulnerability
Published Sep 21, 2026
·Updated
An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menupopup.c components
Affected Software
1 affected component
CrossWire Xiphos<=4.3.2
Event History
Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as exploitable by a local attacker. The available information does not indicate that it can be exploited remotely.
2
Which versions are affected?
CrossWire Xiphos versions up to and including 4.3.2 are identified as affected.
3
What is the impact of successful exploitation?
A successful local exploit can result in arbitrary code execution.
4
Which components should be reviewed when investigating exposure?
The issue involves src/main/url.cc and src/gtk/menu_popup.c. Review the referenced fix commit and these components when assessing whether a build contains the vulnerable behavior.