Deluge: Cross-Site Scripting A vulnerability has been found in Deluge which could result in XSS. deluge 2022-10-16 2022-10-16 866842 remote 2.1.1 2.1.1

Deluge is a BitTorrent client.

Deluge does not sufficiently sanitize crafted torrent file data, leading to the application interpreting untrusted data as HTML.

An attacker can achieve XSS via a crafted torrent file.

There is no known workaround at this time.

All Deluge users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-p2p/deluge-2.1.1"
CVE-2021-3427 ajak ajak