CVE-2025-58766

Source
https://cve.org/CVERecord?id=CVE-2025-58766
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58766.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-58766
Aliases
  • GHSA-7fxm-c5xx-7vpq
Published
2025-09-17T17:36:22.811Z
Modified
2026-04-02T12:56:58.497258Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Dyad Vulnerable to Remote Code Execution via Top-level Navigation in Preview Window
Details

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58766.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/dyad-sh/dyad

Affected ranges

Type
GIT
Repo
https://github.com/dyad-sh/dyad
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/dyad-sh/dyad
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.10.0
v0.11.0
v0.11.1
v0.12.0
v0.12.0-beta.1
v0.12.0-beta.2
v0.13.0
v0.13.0-beta.1
v0.13.0-beta.2
v0.14.0
v0.14.0-beta.1
v0.15.0
v0.15.0-beta.1
v0.15.0-beta.2
v0.16.0
v0.16.0-beta.1
v0.17.0
v0.17.0-beta.1
v0.17.0-beta.2
v0.18.0
v0.18.0-beta.1
v0.18.0-beta.2
v0.19.0
v0.19.0-beta.1
v0.2.0
v0.2.5-beta.1
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.7.5
v0.8.0
v0.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58766.json"