Discussion on CVE-2023–35866 (regarding KeePassXC)
keepassxc.org
keepassxc.org
It seems this principle holds for a lot of things: Try to keep secure storage locked if not in use.
From the top if my head: Our web password vault is 1 xss bug away from being cloned if open. Same for my bank website. Full disk encryption does not help against files like pgpass being read by malware if I am logged in Passwords not in memory can't end up in a core dump. Browser stored passwords also seem vulnerable. Etc....
That would imply that the CVE is that the master password can be gained from an open kdbx, but that hasn't been my understanding, it's just that the contents can be re-saved with a new master password.
Which is more of an analogy to the contents of the safe being vulnerable to be stolen if it's left unlocked.