CVE-2025-12843
MEDIUMwaveterm 0.12.2 - Code Injection via Electron Fuses
Title source: llmDescription
Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.
References (2)
Core 2
Core References
Third Party Advisory, Exploit third-party-advisory
https://fluidattacks.com/advisories/minutos
Product product
https://github.com/wavetermdev/waveterm
Scores
CVSS v3
5.5
EPSS
0.0018
EPSS Percentile
7.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-94
Status
published
Products (1)
waveterm/wave_terminal
0.12.2
Published
Dec 12, 2025
Tracked Since
Feb 18, 2026