CVE-2024-1433
NixOS vulnerability analysis and mitigation

Overview

A path traversal vulnerability was discovered in KDE Plasma Workspace versions up to 5.93.0, identified as CVE-2024-1433. The vulnerability affects the EventPluginsManager::enabledPlugins function in the components/calendar/eventpluginsmanager.cpp file of the Theme File Handler component. The issue was disclosed on February 11, 2024, and allows manipulation of the pluginId argument to achieve path traversal (NVD).

Technical details

The vulnerability exists in the EventPluginsManager::enabledPlugins function where improper validation of the pluginId parameter could lead to path traversal. The issue has been assigned a CVSS v3.1 base score of 3.7 (Low) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N. The vulnerability is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). A fix has been implemented in commit 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01 by using QDir::cleanPath to properly sanitize the pluginId input (Github Commit).

Impact

The vulnerability allows an attacker to load arbitrary .so library files as plasma calendar plugins through directory traversal. This could potentially lead to unauthorized file access and code execution within the context of the affected component. However, the impact is limited as it requires either write access to the user's home directory or the installation of third-party global themes (NVD).

Mitigation and workarounds

The vulnerability has been patched in the KDE Plasma Workspace codebase through commit 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01. The fix involves using QDir::cleanPath to properly sanitize the pluginId parameter. Users are recommended to update to a version that includes this patch (Github Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management