QSearchQSearch

CVE-2026-6891

5.0 MEDIUM

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker wit...

Published: 2026-05-29 · Last updated: 2026-05-29

Severity and scoring

CVSS
5.0 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
CWE
CWE-59

Description

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-54230 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport (7.0 HIGH)
  • CVE-2026-54056 Kitty is a cross-platform GPU based terminal (7.6 HIGH)
  • CVE-2026-54055 Kitty is a cross-platform GPU based terminal (5.0 MEDIUM)
  • CVE-2025-46293 This issue was addressed with improved handling of symlinks (5.5 MEDIUM)
  • CVE-2026-45384 bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files (6.1 MEDIUM)