Arbitrary command execution in Keybase Client for Windows

  • ZSB-21022
  • CVE-2021-34426
  • Medium
  • 5.3
  • CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user’s Git repository could leverage this vulnerability to potentially execute arbitrary Windows commands on a user’s local system.

Users can help keep themselves secure by applying current updates or downloading the latest Keybase software with all current security updates from https://keybase.io/download.

  • All Keybase Client for Windows before version 5.6.0

Reported by RyotaK

Revision Date Description
1.0 12/14/2021

Initial Publication