CVE-2025-34095 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp e…
Critical CVSS: 9.3

CVE-2025-34095

An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp endpoint. An unauthenticated attacker can send a crafted PUT request containing arbitrary Lua os.execute() code, which is then persisted on disk and triggered via a subsequent GET request to examples/manage.lsp. This allows remote command execution on the underlying operating system, impacting both Windows and Unix-based deployments.
Vendor
-
Product
-
CWE
CWE-78
Yayın Tarihi
2025-07-10 20:15:24
Güncelleme
2025-07-15 13:14:49
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar