{"apiVersion":"1.0","identifier":"CVE-2026-81684","description":"In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via the --stego-password argument (on both encrypt and decrypt paths) instead of via an environment variable as done for the main password. Any local user can read the steganography password from /proc/<pid>/cmdline for the lifetime of the subprocess. Fixed in 1.4.9.","publishedAt":"2026-08-27T17:20:57","lastModifiedAt":"2026-08-27T17:20:57","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81684","cvssScore":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","epssProbability":0.00123,"riskScore":0.63,"affectedProduct":"openssl-encrypt","affectedVersions":"<=1.4.8","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-81684","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-81684","en":"https://www.redsauce.net/en/cves/CVE-2026-81684","fr":"https://www.redsauce.net/fr/cves/CVE-2026-81684","pt":"https://www.redsauce.net/pt/cves/CVE-2026-81684","de":"https://www.redsauce.net/de/cves/CVE-2026-81684","sk":"https://www.redsauce.net/sk/cves/CVE-2026-81684","el":"https://www.redsauce.net/el/cves/CVE-2026-81684"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-81684"}}