CVE-2025-57799

Source
https://cve.org/CVERecord?id=CVE-2025-57799
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57799.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57799
Aliases
  • GHSA-qg4r-92hv-g9f4
Published
2025-09-01T15:46:27.137Z
Modified
2026-04-10T05:32:40.199980Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
StreamVault can perform remote command execution
Details

StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the StreamVault-system, an attacker can modify certain system parameters, construct malicious commands, execute command injection attacks against the system, and ultimately gain server privileges. Users of all versions of the StreamVault system to date who have not modified their background passwords or use weak passwords are at risk of having their systems taken over via remote command execution. This issue has been patched in version 250822.

Database specific
{
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57799.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/lemon8866/streamvault

Affected ranges

Type
GIT
Repo
https://github.com/lemon8866/streamvault
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2025.*
2025.07.04
2025.07.10
2025.07.17
2025.07.21
2025.07.24
2025.07.31
2025.08.01
Other
250410
250411
250415
250417
250428
250507
250630
250815
250818
250821
250417.*
250417.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57799.json"