Password-stealing “vulnerability” reported in KeyPass – bug or feature?

Is it a vulnerability if someone with control over your account can mess with files that your account is allowed to access anyway?

from Naked Security https://ift.tt/FxqEsPQ
via IFTTT