GIMP
cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*, +1 more
- < 3.1.4.2
A vulnerability in Nozbe for macOS, related to the 'RunAsNode' fuse being enabled, allows local attackers with unprivileged access to execute arbitrary code that inherits Nozbe's Transparency, Consent, and Control (TCC) permissions. This exploitation could enable access to user files in privacy-protected folders without triggering prompts for permission. The vulnerability affects all versions prior to 2025.11.
Exploitation of this vulnerability allows for arbitrary code execution with the same TCC permissions that Nozbe has been granted by the user, potentially leading to unauthorized access to sensitive files.
Users can update to Nozbe version 2025.11 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.