CVE-2025-55037

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from external sources.
Configurations

No configuration.

History

05 Sep 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-05 06:15

Updated : 2025-09-05 17:47


NVD link : CVE-2025-55037

Mitre link : CVE-2025-55037

CVE.ORG link : CVE-2025-55037


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')