CVE-2022-29281

Source
https://cve.org/CVERecord?id=CVE-2022-29281
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29281.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-29281
Published
2022-04-15T20:41:14Z
Modified
2026-05-28T03:52:43.982019610Z
Summary
[none]
Details

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/29xxx/CVE-2022-29281.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/notable/notable-insiders

Affected ranges

Type
GIT
Repo
https://github.com/notable/notable-insiders
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.9.0-alpha.0
v1.9.0-alpha.1
v1.9.0-alpha.10
v1.9.0-alpha.11
v1.9.0-alpha.12
v1.9.0-alpha.13
v1.9.0-alpha.14
v1.9.0-alpha.15
v1.9.0-alpha.16
v1.9.0-alpha.17
v1.9.0-alpha.18
v1.9.0-alpha.19
v1.9.0-alpha.2
v1.9.0-alpha.20
v1.9.0-alpha.3
v1.9.0-alpha.4
v1.9.0-alpha.5
v1.9.0-alpha.6
v1.9.0-alpha.7
v1.9.0-alpha.8
v1.9.0-alpha.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-29281.json"