CVE-2018-18629: Keybase

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.

Affected products

  • Keybase Keybase: before 2.8.0-20181023124437 (fixed in 2.8.0-20181023124437)

Published 2018-12-20. Last modified 2026-06-17.