PT-2026-26688 · Squidowl · Halloy
Published
2026-03-20
·
Updated
2026-03-20
·
CVE-2026-32810
CVSS v4.0
4.8
Medium
| AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Halloy is an IRC application written in Rust. In versions on *nix and macOS prior to commit f180e41061db393acf65bc99f5c5e7397586d9cb, halloy creates its config directory and files using default umask permissions, which typically results in
0644 on files and 0755 on directories. This allows any local user on the system to read plaintext credentials stored in config.toml or referenced password file paths. Commit f180e41061db393acf65bc99f5c5e7397586d9cb patches the issue.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Halloy