{"id":"CVE-2019-12761","aliases":["GHSA-r6v3-hpxj-r8rv","PYSEC-2019-199","SNYK-PYTHON-PYXDG-174562"],"url":"https://o3.security/vulnerability/CVE-2019-12761","summary":"Code Injection in PyXDG","details":"A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.","published":"2019-06-06T19:29:00.533Z","modified":"2026-03-13T22:15:35.156336Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"pyxdg","fixedVersion":"0.26"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/06/msg00006.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2021/08/msg00003.html"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-PYTHON-PYXDG-174562"},{"type":"EVIDENCE","url":"https://gist.github.com/dhondta/b45cd41f4186110a354dc7272916feba"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-13T22:15:35.156336Z"}}