lowCVSS 3.8Vulnerability

GHSA-2p6r-x3vv-xqm2

rpassword maintainers were made aware of a possible issue with a partial password reveal when input is interrupted. To quote @squell: > @conradkleinespel I've confirmed this problem with SequoiaPGP, which I think uses rpassword, e.g.: > > Suppose we use pkill -9 sq in a different terminal right after the password has been typed in: > > $ sq key generate --userid "barf" --with-password > Enter password to protect the key: Killed > $ hello^C > > Where the password I typed in is "hello". This has been fixed in version v7.5.0 and above.

Properties

ghsa_id
GHSA-2p6r-x3vv-xqm2
severity
low
summary
rpassword affected by partial password reveal when input is interrupted
cvss_score
3.8
cve_id
GHSA-2p6r-x3vv-xqm2
cvss_vector
CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-05-06T21:49:33Z
source_url
https://github.com/advisories/GHSA-2p6r-x3vv-xqm2
ghsa_updated
2026-05-06T21:49:34Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]rust/rpassword

AFFECTS (1)

[Software]rust/rpassword

HAS_WEAKNESS (2)

[Weakness]Improper Handling of Exceptional Conditions
[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-2p6r-x3vv-xqm2 (CVSS 3.8) — Ninja Signal Threat Intelligence | Ninja Signal