CVE-2019-15716: Wtfutil Wtf
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.
Affected products
- Wtfutil Wtf: before 0.19.0 (fixed in 0.19.0)
Published 2019-08-28. Last modified 2026-06-17.