cvedb.io
CVE-2022-4055
HIGH · CVSS 7.4
EPSS exploitation probability: 0%
Published 2022-11-19T00:15:31.003 · Last modified 2026-06-17T05:19:51.697

Summary

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

Affected products

freedesktop — xdg-utils

Does this affect you?

Add your gear to cvedb and we'll alert you only when freedesktop ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.