PT-2026-23736 · Cryptomator · Cryptomator

Infe0

·

Published

2026-03-06

·

Updated

2026-03-06

·

CVE-2026-29110

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cryptomator versions prior to 1.19.0
Description Cryptomator encrypts data stored on cloud infrastructure. Before version 1.19.0, in non-debug mode, Cryptomator could log cleartext file paths. This could reveal metadata about files within a vault when the vault is closed. Cleartext paths are only logged if a filesystem request fails, such as when an encrypted file is damaged or does not exist.
Recommendations Update to version 1.19.0 or later.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2026-29110
GHSA-J83J-MWHC-RCGW

Affected Products

Cryptomator