A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
References
| Link | Resource |
|---|---|
| https://te.mpe.st/disclosures/20260510-simplex.html |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 21:16
Updated : 2026-09-09 16:04
NVD link : CVE-2026-52103
Mitre link : CVE-2026-52103
CVE.ORG link : CVE-2026-52103
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
