{"id":"ECHO-1b2e-ba53-a2b7","summary":"CVE-2020-27748 is fully addressed by the CVE-2022-4055 fix (already applied).\nThe vulnerability existed in the run_thunderbird() function which parsed attach=\nparameters from mailto URIs. The CVE-2022-4055 patch (MR #58) completely removed\nrun_thunderbird(), all Thunderbird detection/dispatch code, and the --attach CLI\noption. Since the entire vulnerable code surface has been deleted, CVE-2020-27748\ncannot be exploited.\n","modified":"2026-09-15T00:47:34.190694368Z","published":"2026-02-09T12:17:24.201482Z","withdrawn":"2026-02-12T14:30:03.942Z","upstream":["CVE-2020-27748"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2020-27748"}],"affected":[{"package":{"name":"xdg-utils","ecosystem":"Echo","purl":"pkg:deb/echo/xdg-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.1-2+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-1b2e-ba53-a2b7.json"}}],"schema_version":"1.9.0"}