CVE-2026-48097

Source
https://cve.org/CVERecord?id=CVE-2026-48097
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48097.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-48097
Aliases
  • GHSA-vx6r-vwjq-567w
Published
2026-08-07T19:06:22.730Z
Modified
2026-08-09T03:47:19.798289593Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
NexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command Execution
Details

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a command execution vulnerability due to unsafe use of shell=True with commands that rely on executable resolution through the PATH environment variable. An attacker controlling the execution environment can place malicious executables such as sudo earlier in the PATH, resulting in execution of attacker-controlled code. Version 2.0.0 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-476",
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48097.json",
    "cna_assigner": "GitHub_M",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "2.0.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/0x5t4l1n/nextor_ip_changer

Affected ranges

Type
GIT
Repo
https://github.com/0x5t4l1n/nextor_ip_changer
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48097.json"