CVE-2016-2087: Hexchat Project Hexchat

High severity, CVSS 7.4. EPSS: 9.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.

Affected products

Published 2017-01-18. Last modified 2026-06-17.