Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-81685: openssl_encrypt before 1.4.9 can show fake delete warnings
CVE-2026-81685 · published 1 month ago
Summary
Versions of openssl_encrypt older than 1.4.9 do not clean up certain data in the desktop interface, so a crafted encrypted file can make the confirmation dialog display misleading text. This could cause users to delete or keep files based on false information. Upgrade to version 1.4.9 or later to resolve the issue.
What to do
- Update jahlives openssl_encrypt to version 1.4.9 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jahlives | openssl_encrypt | < 1.4.9 |
Original advisory text
openssl_encrypt before 1.4.9 Text Injection via Recovery Slot Metadata
openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal confirmation dialog. Attackers can craft encrypted files with malicious slot identifiers containing bidi overrides or line-separator characters to forge warning text and deceive users during file removal operations.
References
- https://github.com/jahlives/openssl_encrypt/security/advisories/GHSA-49h2-qmcq-w... Vendor Advisory
- https://www.vulncheck.com/advisories/openssl-encrypt-before-1.4.9-text-injection... Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81685... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-81685 Vendor Advisory
Severity
9.3
Critical
CVSS 3.1: 3.3 (MITRE)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-116Improper Encoding or Escaping of Output
Timeline
Published27 Aug 2026
Updated27 Sep 2026
First seen27 Aug 2026
Track software like this
Free during beta