lowCVSS 3.8Vulnerability
GHSA-2p6r-x3vv-xqm2
rpassword maintainers were made aware of a possible issue with a partial password reveal when input is interrupted. To quote @squell: > @conradkleinespel I've confirmed this problem with SequoiaPGP, which I think uses rpassword, e.g.: > > Suppose we use pkill -9 sq in a different terminal right after the password has been typed in: > > $ sq key generate --userid "barf" --with-password > Enter password to protect the key: Killed > $ hello^C > > Where the password I typed in is "hello". This has been fixed in version v7.5.0 and above.
Properties
- ghsa_id
- GHSA-2p6r-x3vv-xqm2
- severity
- low
- summary
- rpassword affected by partial password reveal when input is interrupted
- cvss_score
- 3.8
- cve_id
- GHSA-2p6r-x3vv-xqm2
- cvss_vector
- CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-05-06T21:49:33Z
- source_url
- https://github.com/advisories/GHSA-2p6r-x3vv-xqm2
- ghsa_updated
- 2026-05-06T21:49:34Z
Related Entities (5)
VULNERABLE_TO (1)
←[Software]rust/rpassword
AFFECTS (1)
→[Software]rust/rpassword
HAS_WEAKNESS (2)
→[Weakness]Improper Handling of Exceptional Conditions
→[Weakness]Exposure of Sensitive Information to an Unauthorized Actor
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph