ECHO-1b2e-ba53-a2b7

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-1b2e-ba53-a2b7.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-1b2e-ba53-a2b7
Upstream
Withdrawn
2026-02-12T14:30:03Z
Published
2026-02-09T12:17:24Z
Modified
2026-09-15T00:47:34Z
Summary
CVE-2020-27748 is fully addressed by the CVE-2022-4055 fix (already applied). The vulnerability existed in the run_thunderbird() function which parsed attach= parameters from mailto URIs. The CVE-2022-4055 patch (MR #58) completely removed run_thunderbird(), all Thunderbird detection/dispatch code, and the --attach CLI option. Since the entire vulnerable code surface has been deleted, CVE-2020-27748 cannot be exploited.
Details
References

Affected packages

Echo / xdg-utils

Package

Name
xdg-utils
Purl
pkg:deb/echo/xdg-utils

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.2.1-2+e1

Database specific

source
"https://advisory.echohq.com/osv/ECHO-1b2e-ba53-a2b7.json"