CVE-2013-5725: Metaclassy Byword

Medium severity, CVSS 5.0. EPSS: 1.1% chance of exploitation in the next 30 days.

The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.

Affected products

  • Metaclassy Byword: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only

Published 2013-10-01. Last modified 2026-06-16.