XMR
← All projectsMonero Project

Monero GUI

Official graphical Monero wallet and its release-build integration.

MoneroPrivacy protocolsSoftware walletsNormal
Repository coverage

138 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

12security candidates46second-pass queue58AI analyses
34commits · 30 days
43commits · 60 days
110commits · 180 days
138commits · 365 days
Backfill bands
Sep 27 → Mar 3127 seen0 candidatesComplete
Mar 31 → Jul 2961 seen8 candidatesComplete
Jul 29 → Aug 287 seen2 candidatesComplete
Aug 28 → Sep 2715 seen1 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

49/100 average clarity
6Strong · 80–100
14Adequate · 60–79
101Thin · 40–59
17Opaque · 0–39
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Thomas636178
selsta81628048
tobtoht2328052
Cole Munz111073
SChernykh10010028
jpk68902046
plowsof403051
наб100081
munzzyy100083
reservedbytes100050
Balló György100068
Analysis record

Published AI watches

Last scanned 8 minutes ago

Moderate 59 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4645

This change fixes a bug in the Monero wallet setup wizard. Previously, when restoring or creating a wallet from seed/keys, the wallet was first saved with a blank or temporary password before the user's chosen password was applied. If appl…

Wallet file created with empty/blank password before user password is appliedFailure to set user password does not prevent wallet file from being savedSensitive on-disk artifact (wallet file) may be protected by weaker credentials than intended
d7c2f13dby tobtoht+14−93 files
No security note in commit
Informational 17 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4687

This commit updates the Monero GUI wallet's message-signing screen so that when a user verifies a signature, the app now reports extra details: whether the signature is valid, which key type was used (spend key, view key, or unknown), and …

UI-only change to signature verification feedbackNo modification to cryptographic verification logicNew method exposes already-existing signature metadata (key type, version, old algorithm flag)
485a102cby tobtoht+50−133 files
No security note in commit
Low 35 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4709

This change adjusts how the Monero GUI wallet stores and passes login credentials for remote daemon connections. Previously, daemon username/password and 'trusted daemon' status were kept as persistent properties on the wallet object and r…

Credential scoping/lifetime reductionRemoval of persistent daemon login state from wallet objectDefense against cross-connection credential reuse
a5c305deby tobtoht+7−63 files
No security note in commit
Informational 19 AI analysisMessage 59 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4693

This commit fixes a display bug in the Monero GUI wallet's transaction history. Previously, when sorting transactions by block height, failed transactions were incorrectly treated like pending ones and shown at the top of the list. The fix…

UI display logic correction for transaction state classificationTightened conditional for treating transactions as pendingNo memory safety, cryptographic, or authorization changes observed
baef8be9by tobtoht+14−52 files
No security note in commit
Informational 15 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4692

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments with multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it …

0f8a1cf4by tobtoht+84−185 files
No security note in commit
Moderate 58 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4690

This update fixes a timing bug in the Monero wallet's send screen. If a user quickly changed or cancelled a payment while a transaction was still being prepared in the background, the wallet could accidentally show or use the wrong transac…

Race condition between asynchronous transaction creation and UI state changesUse-after-free / dangling pointer risk from stale PendingTransaction objectsPotential wrong-transaction confirmation or commit due to stale async result
c72adf62by tobtoht+57−243 files
No security note in commit
Informational 21 AI analysisMessage 51 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Merge pull request #4665

This commit adds a feature that lets users scan a QR code to restore a Monero wallet from its secret keys. The change itself is a feature addition, not a fix for a known vulnerability. There is one minor security-relevant detail: the QR co…

New QR URI parser handles secret keys (secret_view_key, secret_spend_key) and restore heightAddress validation is performed before accepting parsed restore URIScheme changed from monero_wallet: to monero-wallet:
68327c0aby tobtoht+52−13 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

p2pool v4.18.1

This commit simply updates the Monero GUI wallet's built-in downloader to fetch a newer version of the bundled P2Pool mining software (from v4.18 to v4.18.1) and updates the matching file hashes. There is no indication in the commit itself…

8d95b8a4by SChernykh+12−121 file
No security note in commit
Low 34 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Wallet: keep daemon credentials scoped to each connection

This commit changes how the Monero GUI wallet stores and uses login credentials for remote nodes (servers that help the wallet talk to the Monero network). Previously, the wallet kept daemon username/password as persistent wallet-level set…

Credential scoping change: daemon username/password no longer stored as persistent wallet state for connection reuseRemoval of setDaemonLogin() call from QML remote-node selection pathDaemon credentials now captured per-init and passed directly to underlying wallet implementation
10b08b3bby selsta+7−63 files
No security note in commit
Informational 19 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

TransactionHistoryModel: only place pending tx first

This commit fixes a display bug in the Monero GUI wallet's transaction history list. Previously, failed transactions were being shown at the top of the list alongside pending transactions, because any transaction without a confirmed block …

UI presentation bug, not a memory-safety or cryptographic issueNo attacker-controlled input parsing changedNo privilege escalation, authentication, or authorization logic modified
27328f36by selsta+6−51 file
No security note in commit
Informational 15 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

History: improve display of transactions with multiple recipients

This commit is a user-interface improvement for the Monero GUI wallet's transaction history screen. It changes how outgoing payments to multiple recipients are displayed, searched, and copied. There is no security vulnerability here; it is…

a3dc3882by selsta+84−185 files
No security note in commit
Low 42 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Wallet: fix send confirmation stale transaction race

This patch fixes a race condition in the Monero GUI wallet's send screen. If a user quickly changed send details or canceled a transaction while an earlier transaction was still being prepared in the background, the wallet could mix up the…

Race condition between asynchronous transaction creation and UI state changesPotential use of stale PendingTransaction object after cancellation/replacementMemory leak via undisposed PendingTransaction objects on rejection paths
3f2d9794by selsta+57−243 files
No security note in commit
Informational 15 AI analysisMessage 35 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

workflows: fix Windows build

This is a routine GitHub Actions CI fix for the Windows build. It adds the 'rust:p' package to the list of MSYS2 packages installed during the build. There is no security-relevant change visible in the diff.

dc9f980bby selsta+1−11 file
No security note in commit
Moderate 59 AI analysisMessage 45 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

updater: use proxy for signed hash downloads

This change fixes a privacy leak in the Monero GUI wallet's update checker. Previously, when the wallet checked for updates and downloaded the signed list of official file hashes, it did not route that request through the user's configured…

Privacy leak: update metadata fetch bypassed user-configured proxyProxy setting now propagated to signed hash download pathPotential deanonymization of users who rely on proxy for network privacy
5e5ea68fby selsta+19−67 files
No security note in commit
Informational 15 AI analysisMessage 28 · Opaque
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

p2pool v4.18

This commit simply updates the Monero GUI's built-in downloader to fetch a newer version (4.18) of the bundled P2Pool mining software. It changes download URLs and the expected file hashes to match the new release. There is no indication o…

ddd080e3by SChernykh+12−121 file
No security note in commit
Moderate 58 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

Transfer: disable offline signing for hardware wallets

This commit removes the 'Sign (offline)' button for hardware wallets in the Monero GUI wallet. The change prevents users from attempting an unsupported operation that could lead to failed or unsafe transactions when using a Ledger/Trezor-l…

UI control disabled for hardware-wallet-backed walletsReported by external party (zkao / zkSecurity)Prevents use of an operation likely unsupported by hardware wallet signing flow
66fab82cby selsta+1−11 file
No security note in commit
Informational 15 AI analysisMessage 45 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: simplify restore QR scanner layout

This commit is a straightforward user-interface cleanup in the Monero wallet restore wizard. It replaces a third radio-button option ('Restore from QR Code') with a dedicated QR scan button, simplifying the layout. There is no security-rel…

88324856by selsta+14−151 file
No security note in commit
Low 27 AI analysisMessage 50 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: support key-based monero-wallet restore QR codes

This commit adds a feature to the Monero GUI wallet that lets users scan a QR code to restore a wallet from its secret keys. The change itself is a feature addition, not a direct security fix. However, it handles extremely sensitive data (…

Parsing of URI-encoded secret key material from QR codesManual URI/query-string parsing instead of using a hardened parserUse of decodeURIComponent on untrusted QR code data
a33f2421by selsta+52−13 files
No security note in commit
Informational 23 AI analysisMessage 68 · Adequate
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

wizard: fix restore from QR code

This commit fixes a broken feature in the Monero wallet's setup wizard that restores a wallet by scanning a QR code. The feature had been completely non-functional since a prior redesign because the code that processes the scanned QR code …

No security-relevant signals in the diff or commit messageFixes a broken user-facing feature (restore from QR code)Adds null-safety for extra_parameters to prevent crashes on bare-address QR codes
fbe4c084by Thomas+18−252 files
No security note in commit
Informational 15 AI analysisMessage 55 · Thin
XMR Monero ProjectMonero GUI MoneroPrivacy protocolsSoftware wallets

tests: add QML wallet wizard coverage

This commit adds automated user-interface tests for the Monero wallet setup wizard. It does not change how real users create or open wallets; it only adds test code and exposes a few internal UI control names so the tests can interact with…

0eef8dacby selsta+686−217 files
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Lower-priorityqml: replace XmlListModel for languagesby selsta · 5e475981 · Jul 5, 2026 · 8 filesMessage 45 · ThinTriage 0Details
Commit message · selsta

qml: replace XmlListModel for languages

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityqml: delay daemon startup dialogby selsta · af996bb8 · Jul 5, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

qml: delay daemon startup dialog

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidatesrc: replace deprecated Qt APIsby selsta · f58ec9d5 · Jul 5, 2026 · 4 filesMessage 45 · ThinInformational 15Details
Commit message · selsta

src: replace deprecated Qt APIs

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathboot or update path
AI analysis · Informational 15/100

This commit is a routine code cleanup that swaps out old Qt programming interfaces for their newer replacements. It does not fix a security bug and does not introduce any obvious security weakness. The changes are purely about keeping the code compatible with newer versions of the Qt toolkit.

Lower-prioritymain: allow graceful application shutdownby selsta · e9dd2a3a · Jul 5, 2026 · 4 filesMessage 45 · ThinTriage 0Details
Commit message · selsta

main: allow graceful application shutdown

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedbuild: remove direct X11 dependencyby selsta · d553d5fd · Jul 5, 2026 · 3 filesMessage 80 · StrongInformational 17Details
Commit message · selsta

build: remove direct X11 dependency

X11 was only used for Caps Lock detection on Linux. This small feature does
not justify linking against X11 directly, especially as the upcoming Qt6
migration should avoid unnecessary platform-specific dependencies.

Return false on platforms without native Caps Lock support instead. The
existing X11-based implementation would not work on Wayland anyway.

Also fix the Windows check to mask the Caps Lock toggle bit explicitly.

80/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides detailed explanatory context
Why it was queued
second-pass: broader security terminology
AI analysis · Informational 17/100

This commit removes the Monero GUI wallet's direct dependency on the X11 graphics library on Linux. Previously, X11 was used only to detect whether Caps Lock is on when the user types their password. After the change, Linux systems without native Caps Lock support (including Wayland) will simply report that Caps Lock is off. The commit also fixes a minor Windows Caps Lock check so it correctly reads the on/off toggle bit. There is no obvious security vulnerability here, but users on Linux without native support may get less warning when Caps Lock is active.

Lower-prioritybuild: prepare v0.18.5.1by selsta · 9c76f099 · Jul 2, 2026 · 4 filesMessage 50 · ThinTriage 0Details
Commit message · selsta

build: prepare v0.18.5.1

50/100 · ThinMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
Lower-prioritySet desktop file name for the applicationby Balló György · db73360e · Jul 2, 2026 · 1 fileMessage 68 · AdequateTriage 0Details
Commit message · Balló György

Set desktop file name for the application

This ensures that the XDG toplevel app ID matches with the desktop file
name, so Wayland compositors could match the window with the application
and show the appropriate icon for them.

68/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Security candidatemain: hide update popup during device passphrase promptby selsta · 8290f5a5 · Jul 1, 2026 · 1 fileMessage 50 · ThinInformational 18Details
Commit message · selsta

main: hide update popup during device passphrase prompt

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
access control
AI analysis · Informational 18/100

This tiny change stops a software-update notification window from appearing while the user is entering their hardware wallet passphrase. The most likely real-world effect is avoiding a confusing or annoying overlap of two popups, not a serious security flaw. There is no direct evidence in the commit that this fixes an exploitable vulnerability.

Lower-priorityshare: remove hyphen in .desktop fileby jpk68 · 920faf56 · Jun 30, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · jpk68

share: remove hyphen in .desktop file

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedp2pool v4.17.1by SChernykh · f4bfb444 · Jun 28, 2026 · 1 fileMessage 28 · OpaqueInformational 20Details
Commit message · SChernykh

p2pool v4.17.1

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 20/100

This commit simply updates the Monero GUI's built-in downloader to fetch a newer version of the bundled P2Pool mining software (from v4.17 to v4.17.1) and refreshes the expected file hashes accordingly. There is no code change to how downloads are verified or installed, and no security relevance is stated by the project.

Lower-prioritydocker: update libgpg-error and libgcrypt repoby selsta · 2f61d868 · Jun 26, 2026 · 3 filesMessage 45 · ThinTriage 0Details
Commit message · selsta

docker: update libgpg-error and libgcrypt repo

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityTransfer, AddressBook: confirm unauthenticated OpenAliasby selsta · 23930cb0 · Jun 26, 2026 · 3 filesMessage 50 · ThinTriage 0Details
Commit message · selsta

Transfer, AddressBook: confirm unauthenticated OpenAlias

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
AI review queuedwizard: check wallet file directory is writeableby plowsof · 123433dd · Jun 25, 2026 · 3 filesMessage 45 · ThinLow 29Details
Commit message · plowsof

wizard: check wallet file directory is writeable

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Low 29/100

This commit adds a simple user-facing check in the Monero wallet setup wizard: before creating a wallet, the app now verifies that the chosen folder exists and can be written to. Previously, the wizard only checked whether a location was selected, not whether it was usable. This is a defensive hardening fix that prevents user confusion and possible failed wallet creation, rather than a fix for an active attack.

AI review queuedFix "Quick Layouts recursive rearrange" spam on startupby plowsof · 0d37ac67 · Jun 24, 2026 · 2 filesMessage 50 · ThinInformational 15Details
Commit message · plowsof

Fix "Quick Layouts recursive rearrange" spam on startup

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 15/100

This commit fixes a user-interface layout bug in the Monero wallet application. It stops repeated 'Quick Layouts recursive rearrange' warning messages from appearing on startup by changing how text input fields size themselves. There is no security issue here.

Security candidateDockerfiles: pin Qt to a commit hashby Thomas · 5564db67 · Jun 23, 2026 · 3 filesMessage 76 · AdequateModerate 66Details
Commit message · Thomas

Dockerfiles: pin Qt to a commit hash

Qt was cloned with -b ${QT_VERSION} --depth 1 but, unlike every other
dependency in these files, never reset to a commit, so a moved upstream
tag would silently change the Qt source built into the release.

Pin the qt5 superproject to its v5.15.19-lts-lgpl commit and let it
resolve the submodules (git submodule update on linux/windows,
init-repository on android), so only the qt5 hash is hardcoded. qt5
records the exact submodule commits, and the relative .gitmodules URLs
keep the fetches on https.

Follow-up to #4613.

76/100 · AdequateMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access control
AI analysis · Moderate 66/100

This change tightens how the Monero GUI's build containers fetch the Qt user-interface library. Previously, the build scripts downloaded Qt using only a version tag (like 'v5.15.19-lts-lgpl'), which could silently point to different code if Qt's maintainers ever moved or re-created that tag. Now the scripts reset the downloaded Qt source to a specific, fixed commit hash, so every release build uses the exact same Qt code. This is a supply-chain hardening fix: it prevents a malicious or accidental tag change from slipping modified Qt code into Monero's official wallets.

AI review queuedDockerfiles: fetch dependencies over https instead of git:// / http://by Thomas · 3c3f73c9 · Jun 22, 2026 · 3 filesMessage 81 · StrongModerate 60Details
Commit message · Thomas

Dockerfiles: fetch dependencies over https instead of git:// / http://

The release Dockerfiles cloned Qt (code.qt.io) and libgpg-error/libgcrypt
(git.gnupg.org) over unauthenticated git://, and fetched libiconv
(ftp.gnu.org) over http://. Qt is tag-pinned only, so a MITM on its clone
could substitute source into the build. Switch them all to https, like
every other dependency in these files. The gnupg commit pins and the
libiconv sha256sum are unchanged.

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: broader security terminology
AI analysis · Moderate 60/100

This commit changes how the Monero GUI's release build containers download some important software libraries. Previously, several libraries were downloaded over unencrypted or unauthenticated connections (git:// and http://), which could allow a network attacker to tamper with the downloaded code before it was compiled into Monero's release binaries. The commit switches those downloads to https, which provides encryption and server authentication. The commit message explicitly notes that the Qt library was only pinned by tag, so a man-in-the-middle attacker could have substituted malicious Qt source code into the build. The other libraries (libgpg-error, libgcrypt, libiconv) had additional integrity checks (commit hash pins or sha256sum), so the practical risk there was lower, but the change still removes an unnecessary weak link.

AI review queuedp2pool v4.17by SChernykh · b3e94237 · Jun 21, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · SChernykh

p2pool v4.17

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply updates the Monero GUI's built-in downloader to fetch a newer version of the bundled P2Pool mining software (from version 4.16 to 4.17) and updates the matching file hashes accordingly. There is no code change to how downloads are verified or installed, and no security issue is visible in the diff itself.

Security candidateTransactionHistory: prevent CSV formula injection in writeCSVby Thomas · 0fbb1716 · Jun 18, 2026 · 1 fileMessage 73 · AdequateHigh 70Details
Commit message · Thomas

TransactionHistory: prevent CSV formula injection in writeCSV

writeCSV wrote the transaction note and subaddress label into the CSV
stripping only the quote character. A cell beginning with =, +, - or @
can be interpreted as a formula by spreadsheet software on open, which
CSV quoting does not prevent.

The transaction note can be attacker-controlled: a payment request's
tx_description is stored as the note when the payment is sent, so a
crafted note can run a spreadsheet formula when the user later exports
and opens their history, potentially enabling data exfiltration or
command execution.

Prefix affected fields with a single quote so they are treated as text;
fields beginning with whitespace or a control character are prefixed too.

Co-authored-by: selsta <selsta@sent.at>

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
Why it was queued
explicit security languageprivacy or spend-authorization protocolsigning or wallet path
AI analysis · High 70/100

This update fixes a security flaw in the Monero GUI wallet's export feature. When users exported their transaction history to a CSV file, the wallet stripped quote marks from transaction notes and address labels but did nothing else. If an attacker tricked a user into sending a payment with a specially crafted note beginning with =, +, -, or @, that note could become a spreadsheet formula. When the victim later exported and opened the CSV in Excel or similar software, the formula could run, potentially stealing data or running commands. The fix prefixes risky fields with a single quote so spreadsheets treat them as plain text.

Security candidateqml: escape untrusted text in remaining RichText viewsby Thomas · 3d3a391e · Jun 18, 2026 · 4 filesMessage 85 · StrongModerate 66Details
Commit message · Thomas

qml: escape untrusted text in remaining RichText views

Extends the escaping from commit 23ec5eb6 to the RichText sinks it did
not cover: the transaction note in the tx details popup (History), the
wallet name and account label in the send confirmation
(TxConfirmationDialog), the address label on the merchant page
(Merchant), and the wallet path on the info page (SettingsInfo). These
were interpolated unescaped, so a value containing markup is rendered as
rich text.

The transaction note is the notable case: it can be set from a payment
request's tx_description, so it is attacker influenced.

Escape these fields with Utils.htmlEscape. Set the send confirmation
From field to Text.RichText explicitly so the escaped entities decode in
both of its branches; the single-account branch contains no tag and
would otherwise render as plain text and show the raw entity.

85/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
Why it was queued
explicit security language
AI analysis · Moderate 66/100

This commit fixes a bug where user-controlled text was being displayed as rich text in several places in the Monero wallet app. Rich text can include hidden instructions, fake links, or misleading formatting. The most important case is the transaction note, which can be supplied by someone sending you a payment request, so an attacker could potentially use it to trick you. The fix escapes that text so it is shown as plain characters rather than interpreted as formatting or code.

AI review queuedP2Pool v4.16by SChernykh · 1c49150f · Jun 13, 2026 · 1 fileMessage 28 · OpaqueInformational 15Details
Commit message · SChernykh

P2Pool v4.16

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI analysis · Informational 15/100

This commit simply updates the version of P2Pool that the Monero GUI wallet automatically downloads, from version 4.15.1 to version 4.16. It changes the download URLs, filenames, and the expected SHA-256 hash values for each supported operating system. There is no indication in the commit itself that this is a security fix or that the hashes are wrong.

AI review queuedlibwalletqt: start wallet refresh worker lazilyby selsta · bfce02b5 · Jun 5, 2026 · 2 filesMessage 45 · ThinInformational 11Details
Commit message · selsta

libwalletqt: start wallet refresh worker lazily

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI analysis · Informational 11/100

This change moves the start of a background wallet refresh thread from object creation time to the first time refresh is actually requested. It is a performance and resource-management improvement, not a security fix. There is no indication in the commit that it addresses a vulnerability.

AI review queuedlibwalletqt: capture background sync password by valueby selsta · 16276615 · Jun 3, 2026 · 1 fileMessage 50 · ThinModerate 57Details
Commit message · selsta

libwalletqt: capture background sync password by value

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: broader security terminologysecond-pass: security-sensitive path
AI analysis · Moderate 57/100

This commit changes how a wallet password is passed into a background task. Previously, the password was captured by reference (a pointer to the original variable), which could mean the task reads from memory that is no longer valid if the original variable is destroyed before the task runs. Now it is captured by value, making a safe copy. This is a defensive fix that may prevent a use-after-free or read of stale memory, but the commit itself does not prove an exploitable vulnerability exists.

Lower-priorityworkflows: switch to ucrt runtime for msys2by selsta · 2d943acb · Jun 2, 2026 · 4 filesMessage 45 · ThinTriage 0Details
Commit message · selsta

workflows: switch to ucrt runtime for msys2

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Lower-priorityworkflows: install unbound on macOSby selsta · 3e7e08a1 · Jun 1, 2026 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · selsta

workflows: install unbound on macOS

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedQR: skip QImage padding when filling quirc bufferby selsta · be9eadef · May 26, 2026 · 2 filesMessage 45 · ThinLow 47Details
Commit message · selsta

QR: skip QImage padding when filling quirc buffer

also update quirc submodule

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
parser or protocol pathsecond-pass: security-sensitive path
AI analysis · Low 47/100

This commit fixes a bug in how the Monero GUI's QR code scanner copied image data into the quirc QR decoder library. Previously, the code copied the entire QImage buffer byte-for-byte, including padding bytes that Qt adds at the end of each image row. The new code copies each row individually, skipping the padding. This could have caused quirc to misread QR codes or, in a worst-case scenario, feed malformed data to the decoder. There is no direct evidence in the commit of an exploitable security vulnerability such as memory corruption.