CVE-2025-12556High· 8.8▾ TwilightAn argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary code within the context of the host machine.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40938High· 7.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines
CVE-2025-62847High· 7.5An improper neutralization of argument delimiters in a command vulnerability has been reported to affect several QNAP operating system versions
CVE-2026-105791High· 7.5Microsoft UFO is an open-source framework for intelligent automation across devices and platforms
CVE-2026-105788High· 8.8Microsoft UFO is an open-source framework for intelligent automation across devices and platforms
CVE-2026-105789Medium· 5.4Microsoft UFO is an open-source framework for intelligent automation across devices and platforms
GHSA-w2vw-w76x-qr89HighNx: OS command injection via git revisions and remote refs