CVE-2017-16043: Shout Project Shout

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.

Affected products

  • Shout Project Shout: from 0.44.0, before 0.50.0 (fixed in 0.50.0)

Published 2018-06-04. Last modified 2026-06-17.