Overview: 1 vulnerability

WSA Score Severity Issue Vulnerability type Scope Versions Fix Release date
WSA-2026-17 6.5
Bypass of user authorization for start of DCC file transfer. Incorrect Authorization Xfer 0.1.4 → 4.10.0 4.10.1

WSA-2026-17: [Xfer] Bypass of user authorization for start of DCC file transfer.

Vulnerability
CVE
Not available
CVSS vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (detail)
CVSS score
6.5 / 10
Severity
medium
Vulnerability type
Incorrect Authorization (detail)
Scope
Xfer
Affected versions
0.1.4 → 4.10.0
Fixed version
4.10.1 () - ChangeLog
Tracker
Commits
Description
When resuming a DCC file transfer, a peer can start it without user manual acceptance.
Mitigation
Unload xfer plugin with command: /plugin unload xfer and see: /help weechat.plugin.autoload.
Credit
The issue was discovered by Acts1631.