CVE-2025-65199EPSS p68.4%
CVE-2025-65199CVE-2025-65199
windscribe / windscribe
Description
A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.25% probability of exploitation · percentile 68.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |