Loading vulnerability details…
CVSS v3.1
8.6
EPSS
0.35%
Published
Jan 28, 2025
Modified
Aug 6, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (2)
References (5)