VendorsMintty Projectminttyany version
Vulnerabilities

Mintty Project Mintty any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2022-47583
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
Published 2023-10-19 · Modified
9.8EPSS 0.011
CVE-2023-39726
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.
Published 2023-10-26 · Modified
9.8EPSS 0.010
CVE-2025-1052
Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published 2025-02-11 · Analyzed
8.8EPSS 0.010
CVE-2021-28848
Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.
Published 2021-06-03 · Modified
7.5EPSS 0.016
CVE-2021-31701
Mintty before 3.4.7 mishandles Bracketed Paste Mode.
Published 2021-06-06 · Modified
7.5EPSS 0.009