Vulnerabilities > Keybase > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-11-11 CVE-2021-34422 Path Traversal vulnerability in Keybase
The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder.
network
low complexity
keybase CWE-22
critical
9.0
2019-01-31 CVE-2019-7249 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Keybase
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.
network
low complexity
keybase CWE-367
critical
9.8