CVE-2020-26947: Getmonero Monero

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows local users to gain privileges via a Trojan horse library in the current working directory.

Affected products

  • Getmonero Monero: before 0.17.1.0 (fixed in 0.17.1.0)

Published 2020-10-10. Last modified 2026-06-17.