CVE-2012-5534
EPSS 2.0%Published: 12/3/2012Modified: 4/28/2026
Description
The hook_process function in the plugin API for WeeChat 0.3.0 through 0.3.9.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a command from a plugin, related to "shell expansion."
Affected packages (1)
- Debian/weechatfrom 0, < 0.3.9.2-1