Releases148
Frequency6 days 8 hours
Last Release
Stars3.14K
An extensible framework for Personal Data Management.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted eidos: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (eidos:), causing the Eidos application to launch and process the URL, leading to remote code execution on the victim’s machine. This issue does not have a fix as of October 3, 2025