Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."
Metrics
Affected Vendors & Products
References
History
Sun, 10 Aug 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Thor before 1.4.0 can construct an unsafe shell command from library input. | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." |
| References |
|
Tue, 29 Jul 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | thor: Thor Command Injection Vulnerability | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 21 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Jul 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Thor before 1.4.0 can construct an unsafe shell command from library input. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-07-20T00:00:00.000Z
Updated: 2025-08-10T00:19:19.943Z
Reserved: 2025-07-20T00:00:00.000Z
Link: CVE-2025-54314
Updated: 2025-07-21T20:35:48.333Z
Status : Awaiting Analysis
Published: 2025-07-20T03:15:22.160
Modified: 2025-08-10T01:15:32.107
Link: CVE-2025-54314