Fwd: Security vulnerabilities fixed in WeeChat 4.10.1
WeeChat 4.10.1 fixes six security vulnerabilities, including WSA-2026-15 allowing DCC-received files to be written outside the configured directory.
WeeChat 4.10.1, released September 5, 2026, patches six security vulnerabilities tracked via project advisories such as WSA-2026-15. The Xfer issue lets a file received over DCC be written outside the configured directory. The announcement was forwarded by Sam James on the oss-security mailing list, and users should upgrade to 4.10.1.
- WeeChat 4.10.1 (released Sep 5, 2026) fixes six vulnerabilities (WSA-2026-15 onward).
- WSA-2026-15: DCC file transfers can write outside the configured directory.
- Disclosed via project security advisories and relayed on oss-security; upgrade recommended.
Posted by Sam James on Sep 05 -------------------- Start of forwarded message -------------------- Date: Sat, 5 Sep 2026 19:31:16 +0200 From: Sébastien Helleu To: weechat-security () nongnu org Subject: Security vulnerabilities fixed in WeeChat 4.10.1 Hi all, Six security vulnerabilities have been fixed in WeeChat 4.10.1, which was released on September 5th, 2026: - WSA-2026-15: [Xfer] Write of DCC file received outside of configured...
This source does not provide full text. Read it at seclists.org.