xdg-dbus-proxy 0.1.9 fixes sandbox escape CVE-2026-94422
xdg-dbus-proxy 0.1.9 patches sandbox escape CVE-2026-94422; every older release is vulnerable.
Simon McVittie announced on oss-security that xdg-dbus-proxy 0.1.9 fixes CVE-2026-94422, a sandbox escape. All versions older than 0.1.9 are vulnerable. The fix is documented in GitHub advisory GHSA-2cgv-pwcq-wvpq and the 0.1.9 release notes. The notice does not report active exploitation.