


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in tiddly-gittly TidGi-Desktop up to 0.13.0. This impacts an unknown function of the file src/services/wiki/wikiWorker/loadWikiTiddler…
Published:
4 juli 2026 om 22:00:00
Alert date:
5 juli 2026 om 09:01:12
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
A code injection vulnerability has been identified in tiddly-gittly TidGi-Desktop versions up to 0.13.0. The vulnerability exists in the file src/services/wiki/wikiWorker/loadWikiTiddlersWithSubWikis.ts within the Git Repository Import component. An attacker can exploit this vulnerability remotely by manipulating input to achieve code injection. The exploit has been publicly disclosed, increasing the risk of active exploitation. No authentication details are specified, and the exact function affected remains unknown. The public availability of the exploit makes this a high-priority issue for users of the affected software. Users are advised to review the GitHub security advisory and apply any available patches or mitigations promptly.
Technical details
Mitigation steps:
Affected products:
TidGi-Desktop up to 0.13.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-14722
https://github.com/tiddly-gittly/TidGi-Desktop/
https://github.com/tiddly-gittly/TidGi-Desktop/security/advisories/GHSA-9hc2-hjx8-q6pv
https://vuldb.com/cve/CVE-2026-14722
https://vuldb.com/submit/847648
https://vuldb.com/vuln/376309
https://vuldb.com/vuln/376309/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
