CVE-2025-52365
03.03.2026, 15:16
A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system commands via unsanitized user input passed to os.system(). The vulnerability arises from improper input handling where command-line arguments are directly concatenated into shell commands without validation
Awaiting analysis
This vulnerability is currently awaiting analysis.