VulnerabilityAnalyzed
CVE-2025-9176
The manipulation results in os command injection.
LOW 1.9EPSS 1.29%
Does this matter?
Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.
Description
A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of the component Environment Variable Handler. The manipulation results in os command injection. The attack is only possible with local access. The exploit has been released to the public and may be exploited.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.29% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77, CWE-78
- Affected
- neurobin/shc
- Source
- cna@vuldb.com
References
- https://magnificent-dill-351.notion.site/Command-Execution-of-env-in-shc-4-0-3-249c693918ed80c997f4e9420f945d01Broken Link
- https://vuldb.com/?ctiid.320557Permissions Required, VDB Entry
- https://vuldb.com/?id.320557Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.630744Third Party Advisory, VDB Entry
- https://magnificent-dill-351.notion.site/Command-Execution-of-env-in-shc-4-0-3-249c693918ed80c997f4e9420f945d01Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.