Логотип exploitDog
bind:CVE-2025-55294
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-55294

Количество 2

Количество 2

nvd логотип

CVE-2025-55294

6 месяцев назад

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with the privileges of the calling process. This vulnerability is fixed in 1.15.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-gjx4-2c7g-fm94

6 месяцев назад

screenshot-desktop vulnerable to command Injection via `format` option

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-55294

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with the privileges of the calling process. This vulnerability is fixed in 1.15.2.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-gjx4-2c7g-fm94

screenshot-desktop vulnerable to command Injection via `format` option

CVSS3: 9.8
0%
Низкий
6 месяцев назад

Уязвимостей на страницу