OpenRGB: Multiple Vulnerabilities — GLSA 202608-30

Multiple vulnerabilities have been found in OpenRGB, allowing root remote command execution.

Affected packages

app-misc/openrgb on all architectures
Affected versions < 1.0_rc3_p1
Unaffected versions >= 1.0_rc3_p1

Background

OpenRGB is a cross-platform software suite for controlling RGB LED lighting devices.

Description

Multiple vulnerabilities have been discovered in OpenRGB. Please review the CVE identifiers referenced below for details.

Impact

Please review the referenced CVE identifiers for details.

Workaround

There is no known workaround at this time. Users are recommended to avoid exposing OpenRGB to the network even with these fixes.

Resolution

All OpenRGB users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-misc/openrgb-1.0_rc3_p1"
 

References

Release date
August 27, 2026

Latest revision
August 27, 2026: 1

Severity
high

Exploitable
local and remote

Bugzilla entries