### [CVE-2021-32563](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32563) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution. ### POC #### Reference - http://www.openwall.com/lists/oss-security/2023/01/05/1 - http://www.openwall.com/lists/oss-security/2023/01/05/2 #### Github No PoCs found on GitHub currently.