CVE-2012-2085: Gajim

Medium severity, CVSS 6.8. EPSS: 3.2% chance of exploitation in the next 30 days.

The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute.

Affected products

  • Gajim Gajim: up to and including 0.14.4; version 0.1 only; version 0.10 only; version 0.10.1 only; version 0.11 only; version 0.11.1 only; …

Published 2012-08-28. Last modified 2026-06-16.