Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments."
Metrics
Affected Vendors & Products
References
History
Sun, 10 Aug 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Thor before 1.4.0 can construct an unsafe shell command from library input. | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." |
References |
|
Tue, 29 Jul 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | thor: Thor Command Injection Vulnerability | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Mon, 21 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sun, 20 Jul 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Thor before 1.4.0 can construct an unsafe shell command from library input. | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-20T00:00:00.000Z
Updated: 2025-08-10T00:19:19.943Z
Reserved: 2025-07-20T00:00:00.000Z
Link: CVE-2025-54314

Updated: 2025-07-21T20:35:48.333Z

Status : Awaiting Analysis
Published: 2025-07-20T03:15:22.160
Modified: 2025-08-10T01:15:32.107
Link: CVE-2025-54314
