Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."
CVSS
No CVSS.
References
Configurations
No configuration.
History
10 Aug 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." | |
CWE | ||
References |
|
20 Jul 2025, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-20 03:15
Updated : 2025-08-10 01:15
NVD link : CVE-2025-54314
Mitre link : CVE-2025-54314
JSON object : View
Products Affected
No product.
CWE
No CWE.