Executive brief
openssl_encrypt is a tool for encrypting and decrypting files. The desktop GUI version had a flaw that wrote decrypted files with world-readable permissions instead of owner-only permissions. On shared systems with multiple users, other local users could read sensitive decrypted data left behind by the application.
Technical details
The vulnerability is an insecure default file permissions issue (CWE-276) in the desktop GUI component. The GUI used Dart's writeAsString/writeAsBytes methods to write decrypted plaintext, which create files at the process umask (typically 0644, world-readable), whereas the CLI correctly used owner-only permissions (0600). An unprivileged local attacker on a multi-user system can read decrypted output files left by other users running the GUI. The vulnerability affects versions before 1.4.9 and requires local access to the system. The fix in 1.4.9 creates output files with owner-only permissions (0600) before writing content, ensuring plaintext never resides in world-readable files.
Affected products
- jahlives openssl_encrypt before 1.4.9
Timeline
- 2026-08-12: disclosed
- 2026-08-27: patched: Version 1.4.9 released with fix