CVE-2025-49466: Rjarry Aerc

Medium severity, CVSS 5.8. EPSS: 0.6% chance of exploitation in the next 30 days.

aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,

Affected products

Published 2025-06-05. Last modified 2026-06-17.