CVE-2018-17170: Teamwire

High severity, CVSS 8.1. EPSS: 2.6% chance of exploitation in the next 30 days.

Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.

Affected products

  • Teamwire Teamwire: from 1.5.1, before 1.9.0 (fixed in 1.9.0)

Published 2019-06-28. Last modified 2026-06-17.