CVE-2023-43091: Gnome Gnome-Maps

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is malicious, it may execute arbitrary code.

Affected products

  • Gnome Gnome-Maps: from 43.0, before 43.7 (fixed in 43.7); from 44.0, before 44.4 (fixed in 44.4)

Published 2024-11-17. Last modified 2026-06-17.