#VU32965 Command Injection in WebKitGTK+ and WPE WebKit - CVE-2020-9862
Published: August 2, 2020
WebKitGTK+
WPE WebKit
WebKitGTK
Description
The vulnerability allows a remote attacker to execute arbitrary commands on the system.
The vulnerability exists due to improper input validation in Web
Inspector when copying a URL. A remote attacker can trick the victim into copying a specially crafted URL and execute arbitrary commands on the system with privileges of the current user.