CVE detail
CVE-2021-26917 — CVE-2021-26917
Published 2021-02-08 · Modified 2026-06-17 · Vendor bitmessage · Product pybitmessage · Source nvd
MEDIUM
severity
CVSS-derived band
0.0055
EPSS probability
exploitation probability, 30d
43.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted apinotifypath value. NOTE: the discoverer states "security mitigation may not be necessary as there is no evidence yet that these screen intercepts are actually transported away from the local host." NOTE: it is unclear whether there are any common use cases in which apinotifypath is controlled by an attacker
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References