CVE-2024-1433
NixOS vulnerability analysis and mitigation

Overview

A path traversal vulnerability was discovered in KDE Plasma Workspace versions up to 5.93.0, identified as CVE-2024-1433. The vulnerability affects the EventPluginsManager::enabledPlugins function in the components/calendar/eventpluginsmanager.cpp file of the Theme File Handler component. The issue was disclosed on February 11, 2024, and allows manipulation of the pluginId argument to achieve path traversal (NVD).

Technical details

The vulnerability exists in the EventPluginsManager::enabledPlugins function where improper validation of the pluginId parameter could lead to path traversal. The issue has been assigned a CVSS v3.1 base score of 3.7 (Low) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N. The vulnerability is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). A fix has been implemented in commit 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01 by using QDir::cleanPath to properly sanitize the pluginId input (Github Commit).

Impact

The vulnerability allows an attacker to load arbitrary .so library files as plasma calendar plugins through directory traversal. This could potentially lead to unauthorized file access and code execution within the context of the affected component. However, the impact is limited as it requires either write access to the user's home directory or the installation of third-party global themes (NVD).

Exploitability

The vulnerability has a high attack complexity and requires specific preconditions to be exploitable. It can only be triggered via theme files that provide a config for the digital-clock applet which includes 'enabledCalendarPlugins' that uses directory traversal. The attack requires either write access to the user's home directory or the ability to install third-party global themes, making it not directly exploitable without prior access (Github Commit).

Mitigation and workarounds

The vulnerability has been patched in the KDE Plasma Workspace codebase through commit 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01. The fix involves using QDir::cleanPath to properly sanitize the pluginId parameter. Users are recommended to update to a version that includes this patch (Github Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-translations-common
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • firefox-esr
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management