Releases39
Frequency2 months 3 weeks
Last Release
KeePassXC is a fork of [KeePassX](https://www.keepassx.org/) that [aims to incorporate stalled pull requests, features, and bug fixes that have never made it into the main KeePassX repository](https://github.com/keepassxreboot/keepassx/issues/43). ![KeepassXC screenshot](https://cdn.rawgit.com/chocolatey/chocolatey-coreteampackages/f2cfda756d8ab847b9d65ce394de18c6a090666b/automatic/keepassxc/screenshot.png) # Features These are the additional features compared to KeePassX: - Auto-Type on all three major platforms (Linux, Windows, macOS) - Twofish encryption - YubiKey challenge-response support - TOTP generation - CSV import - Command line interface - DEP and ASLR hardening - Stand-alone password and passphrase generator - Password strength meter - Using website favicons as entry icons - Merging of databases - Automatic reload when the database changed on disk - Browser integration with KeePassHTTP-Connector for Mozilla Firefox and Google Chrome or Chromium, and passafari in Safari. - Browser integration with KeePassXC-Browser using native messaging for Mozilla Firefox and Google Chrome or Chromium. ## Notes - **If the package is out of date please check [Version History](#versionhistory) for the latest submitted version. If you have a question, please ask it in [Chocolatey Community Package Discussions](https://github.com/chocolatey-community/chocolatey-packages/discussions) or raise an issue on the [Chocolatey Community Packages Repository](https://github.com/chocolatey-community/chocolatey-packages/issues) if you have problems with the package. Disqus comments will generally not be responded to.**

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 2.7.76.5 MEDIUM

KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

= 2.7.76.5 MEDIUM

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

<= 2.7.55.5 MEDIUM

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated KeePassXC Database session, without the need to authenticate these changes by entering the password and/or second-factor authentication to confirm changes. NOTE: the vendor's position is "asking the user for their password prior to making any changes to the database settings adds no additional protection against a local attacker."