CVE-2025-55037

Source
https://cve.org/CVERecord?id=CVE-2025-55037
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55037.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55037
Aliases
Published
2025-09-05T05:24:41.118Z
Modified
2026-07-15T01:48:49.921752617Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, an arbitrary OS command may be executed by a remote unauthenticated attacker if the settings are configured to construct messages from external sources.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "cna_assigner": "jpcert",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55037.json"
}
References

Affected packages

Git / github.com/kujirahand/tkeasygui-python

Affected ranges

Type
GIT
Repo
https://github.com/kujirahand/tkeasygui-python
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "versions prior to v1.0.22"
        },
        {
            "last_affected": "versions prior to v1.0.22"
        }
    ]
}

Affected versions

versions prior to v1.*
versions prior to v1.0.22

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55037.json"