Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-55294

Опубликовано: 19 авг. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with the privileges of the calling process. This vulnerability is fixed in 1.15.2.

EPSS

Процентиль: 41%
0.00191
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
github
6 месяцев назад

screenshot-desktop vulnerable to command Injection via `format` option

EPSS

Процентиль: 41%
0.00191
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-77