Home

Description

A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system commands via unsanitized user input passed to os.system(). The vulnerability arises from improper input handling where command-line arguments are directly concatenated into shell commands without validation

PUBLISHED Reserved 2025-06-16 | Published 2026-03-03 | Updated 2026-03-03 | Assigner mitre

References

github.com/ccurtsinger/stabilizer/

github.com/ccurtsinger/stabilizer/blob/master/szc

github.com/h1dr1/CVE_Research/blob/main/CVE-2025-52365.md

cve.org (CVE-2025-52365)

nvd.nist.gov (CVE-2025-52365)

Download JSON