PatchSiren

WineHQ CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WineHQ CVE published 2026-05-24

CVE-2026-48831

Wine's .desktop file registers MIME handlers for Windows executable formats (EXE and others). When triggered, these handlers may execute files with the invoker's permissions, enabling sandbox escape from Flatpak and Snap environments. The issue stems from MIME handlers being invoked by file managers or browsers when users interact with executable files, rather than being restricted to intentional program [truncated]