Intel

AIKIDO-2026-953388

slint-viewer is vulnerable to Missing Authentication for Critical Function

Missing Authentication for Critical FunctionGHSA-2jqx-548f-7fj8 Published 5 days ago

54

Medium Risk

This Affects:

RUSTslint-viewer
1.17.0 - 1.17.1
Fixed in 1.18.0
Are you affected? Scan for Free

TL;DR

The slint-viewer --remote preview listener (always on for the Android and iOS viewer, opt-in with --remote on desktop) binds a WebSocket server to the network wildcard address, announces it over mDNS, and its handshake_callback in internal/live-preview/remote/connection.rs accepts any client that offers the version derived PROTOCOL_SUBPROTOCOL string. Any host on the same network can complete that handshake with no token, pairing code, origin check, or TLS, then use the LspToPreviewMessage protocol to push arbitrary .slint content and show it full screen with SetContents/ShowPreview, or pass a crafted .ttf payload into the native font parser through collection.register_fonts with no size, format, or provenance checks. Applications built with Slint do not run this listener and are not affected. The fix pairs the connection with a code shown on the device and encrypts the session that follows.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run slint-viewer with the --remote flag, or use the Android or iOS viewer, on a network shared with untrusted hosts.

Background info

slint-viewer is vulnerable to Missing Authentication for Critical Function in versions 1.17.0 - 1.17.1.

How to fix this

Upgrade the slint-viewer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform