Security: sparkle-project/Sparkle
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Update is validated on the resolved path but moved via the unresolved pathGHSA-3x7w-j75x-ppq5 published
Aug 17, 2026 by zorgiepooHigh -
Root-privileged cache cleanup follows a symlink under the console user's homeGHSA-4v99-qgq9-6pxp published
Aug 17, 2026 by zorgiepooHigh -
Incomplete fix of CVE-2026-47121 - the binary-diff delta sink's symlink-following isWritableFileAtPath: check suppresses the defensive removal, and bspatch opens the output without O_NOFOLLOW, so a same-path symlink item truncates a file outside the destination tree (arbitrary overwrite, root for system installs)GHSA-gmj2-gq3j-vqmj published
Aug 2, 2026 by zorgiepooModerate -
Binary delta apply intermediate-symlink traversal in malicious .deltaGHSA-hg88-v3cw-3qrh published
May 19, 2026 by zorgiepooModerate -
AppInstaller post-stage-1 XPC listener accepts unvalidated connections, allowing spoofed appcast item data injection.GHSA-g3hp-f6mg-559v published
May 19, 2026 by zorgiepooModerate
Learn more about advisories related to sparkle-project/Sparkle in the GitHub Advisory Database