CVE-2020-15692

CRITICAL

Nim 1.2.4 - Command Injection

Title source: llm

Description

In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands.

Scores

CVSS v3 9.8
EPSS 0.0209
EPSS Percentile 83.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-88
Status published

Affected Products (1)

nim-lang/nim < 1.2.6

Timeline

Published Aug 14, 2020
Tracked Since Feb 18, 2026