PatchSiren cyber security CVE debrief
CVE-2017-5589 Yaxim CVE debrief
CVE-2017-5589 is a display-impersonation flaw in yaxim and Bruno for Android. According to the NVD record, an incorrect implementation of XEP-0280: Message Carbons can let a remote attacker make messages appear as if they came from another user, including contacts, which creates a social-engineering risk.
- Vendor
- Yaxim
- Product
- Bruno
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-09
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-09
- Advisory updated
- 2026-05-13
Who should care
Organizations or individuals using yaxim or Bruno on Android, especially versions 0.8.6 through 0.8.8, should care because the flaw can mislead users by spoofing the apparent sender of messages.
Technical summary
The vulnerability is described as an incorrect implementation of XEP-0280 (Message Carbons) in multiple XMPP clients. NVD lists yaxim and Bruno on Android 0.8.6, 0.8.7, and 0.8.8 as affected. The impact is integrity-related display spoofing: a remote attacker can impersonate users in the application’s UI, enabling convincing social-engineering attacks. The CVSS vector provided by NVD is CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N.
Defensive priority
Medium. The issue is network-reachable and can affect trust in message identity, but the documented impact is limited to impersonation in the client display rather than direct code execution or data theft.
Recommended defensive actions
- Upgrade yaxim or Bruno to a version that includes the upstream fix referenced by the project commit.
- If immediate upgrading is not possible, treat sender identity in affected clients with extra caution and verify sensitive requests through an independent channel.
- Review deployments for Android devices running yaxim or Bruno 0.8.6 through 0.8.8 and prioritize them for remediation.
- Use the NVD record and the linked upstream patch reference to confirm the corrected build or release in your environment.
Evidence notes
The NVD CVE record states the issue is an incorrect implementation of XEP-0280: Message Carbons and lists affected CPEs for yaxim and Bruno versions 0.8.6, 0.8.7, and 0.8.8 on Android. The record also references an upstream GitHub patch commit and a third-party technical advisory that discuss the flaw. Published date used here is 2017-02-09, per the supplied CVE timeline.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5589 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5589
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5589 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5589
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/ge0rg/yaxim/commit/65a38dc77545d9568732189e86089390f0ceaf9f
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/
[email protected] - Exploit, Technical Description, Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf
[email protected] - Exploit, Technical Description, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.