CVE-2025-52365
Published
CVSS v3
7.8
HIGH
CVSS v2
N/A
Affected
2
PROJECTS
Description
A command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary system commands via unsanitized user input passed to os.system(). The vulnerability arises from improper input handling where command-line arguments are directly concatenated into shell commands without validation
I publish here minimal POCs and analysis md files of my discovered CVEs and N-days .