1Password CLI Vulnerability

(codeberg.org)

43 points | by manchicken 7 hours ago ago

7 comments

  • robin_reala 33 minutes ago ago

    Sidenote, but nice to see a few more Codeberg links popping up instead doctor ubiquitous GitHub. Maybe we’re decentralising a little more in this area.

  • hollow-moe 5 hours ago ago

    is this just a "vulnerability" in the same way sudo doesn't ask for password for a short time after first use ?

    • kachapopopow an hour ago ago

      only applies to the current terminal session, this applied from any session including build sub-sessions.

      but yah, you're right it's a very low-risk attack.

  • e40 5 hours ago ago

    > Responsible disclosure was made via BugCrowd on 2nd October, 2023, and disclosure was authorized in January of 2024

    I’m confused why this is just be publicly disclosed. It’s been known for 2 years!

    • alwa 5 hours ago ago

      > This investigation took a while, and I waited a while before publishing this disclosure (life circumstances and giving 1Password time to fix the issue).

      Sounds like the person really came from a supportive place and hoped things would get sorted out. And had life intervene along the way maybe.

  • oulipo2 an hour ago ago

    Is the described behavior still the default with `op` cli?

  • lucasqueiroz 6 hours ago ago

    Great work and thank you for sharing! I will definitely disable the CLI integration. Hoping 1Password fixes the CLI flow soon.