A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the keybase git lfs-config command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a users Git repository could leverage this vulnerability to potentially execute arbitrary Windows commands on a users local system.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Keybase | Keybase | * | 5.6.0 (excluding) |