slint-viewer is vulnerable to Missing Authentication for Critical Function
54
Medium Risk
The slint-viewer --remote preview listener (always on for the Android and iOS viewer, opt-in with --remote on desktop) binds a WebSocket server to the network wildcard address, announces it over mDNS, and its handshake_callback in internal/live-preview/remote/connection.rs accepts any client that offers the version derived PROTOCOL_SUBPROTOCOL string. Any host on the same network can complete that handshake with no token, pairing code, origin check, or TLS, then use the LspToPreviewMessage protocol to push arbitrary .slint content and show it full screen with SetContents/ShowPreview, or pass a crafted .ttf payload into the native font parser through collection.register_fonts with no size, format, or provenance checks. Applications built with Slint do not run this listener and are not affected. The fix pairs the connection with a code shown on the device and encrypts the session that follows.
You are affected if you are using a version that falls within the vulnerable range and you run slint-viewer with the --remote flag, or use the Android or iOS viewer, on a network shared with untrusted hosts.
slint-viewer is vulnerable to Missing Authentication for Critical Function in versions 1.17.0 - 1.17.1.
Upgrade the slint-viewer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.