{"id":"CVE-2025-55671","aliases":["GHSA-ph2w-cx28-vhrq","PYSEC-2026-1968"],"title":"TkEasyGUI Affected by Uncontrolled Search Path Element Issue","summary":"TkEasyGUI Affected by Uncontrolled Search Path Element Issue","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"tkeasygui","product":"tkeasygui","ecosystem":"pip","affected":["tkeasygui < 1.0.22"],"patched":["tkeasygui 1.0.22"],"published":"2025-09-05","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-ph2w-cx28-vhrq","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55671"},{"url":"https://github.com/kujirahand/tkeasygui-python"},{"url":"https://github.com/kujirahand/tkeasygui-python/releases/tag/v1.0.22"},{"url":"https://jvn.jp/en/jp/JVN48739895"}],"tags":["osv","pip"],"epss":0.00164,"epssPercentile":0.06075,"ingestedAt":"2026-07-08T18:25:51.776Z","slug":"CVE-2025-55671","body":"## Overview\n\nUncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited, arbitrary code may be executed with the privilege of running the program.\n\n## Affected packages\n\n- `tkeasygui < 1.0.22`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `tkeasygui 1.0.22`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}