CVE-2025-55076

Source
https://cve.org/CVERecord?id=CVE-2025-55076
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55076.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55076
Published
2025-12-03T17:15:52.493Z
Modified
2026-03-13T03:34:11.718576Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55076.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.4.0"
            }
        ]
    }
]