CVE-2025-65199

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:windscribe:windscribe:*:*:*:*:*:linux:*:*
cpe:2.3:a:windscribe:windscribe:2.18.1:alpha:*:*:*:linux:*:*
cpe:2.3:a:windscribe:windscribe:2.18.3:*:*:*:*:linux:*:*
cpe:2.3:a:windscribe:windscribe:2.18.5:*:*:*:*:linux:*:*

History

No history.

Information

Published : 2025-12-10 19:16

Updated : 2025-12-23 15:27


NVD link : CVE-2025-65199

Mitre link : CVE-2025-65199

CVE.ORG link : CVE-2025-65199


JSON object : View

Products Affected

windscribe

  • windscribe
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')