---
id: CVE-2025-65199
title: >-
  A command injection vulnerability exists in Windscribe for Linux Desktop App
  that allows a local user who is a member of the windscribe group to execute
  arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU'
  functi…
summary: >-
  A command injection vulnerability exists in Windscribe for Linux Desktop App
  that allows a local user who is a member of the windscribe group to execute
  arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU'
  functi…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: windscribe
product: windscribe
affected:
  - 'windscribe >= 2.10.1, <= 2.17.10'
  - windscribe = 2.18.1
  - windscribe = 2.18.3
  - windscribe = 2.18.5
published: '2025-12-10'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65199'
references:
  - url: 'https://github.com/Windscribe/Desktop-App'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://github.com/Windscribe/Desktop-App/compare/v2.18.2...v2.18.3?diff=unified&w#diff-57e27ab201a1a612609087b839e03bf87a5a063ffcc3f465a6245469bc102754
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://github.com/Windscribe/Desktop-App/compare/v2.18.2...v2.18.3?diff=unified&w#diff-cfc5df17057ed92112ae70a42c81c57c79f434429210ff881fb0771cf8e39b4c
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://hackingbydoing.wixsite.com/hackingbydoing/post/windscribe-vpn-local-privilege-escalation
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: >-
      https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json
    label: 9119a7d8-5eab-497f-8521-727c672e3725
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-65199'
    label: 9119a7d8-5eab-497f-8521-727c672e3725
tags:
  - nvd
epss: 0.01253
epssPercentile: 0.68198
ingestedAt: '2026-09-25T23:21:16.936Z'
---

## Overview

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.

## Affected

- `windscribe >= 2.10.1, <= 2.17.10`
- `windscribe = 2.18.1`
- `windscribe = 2.18.3`
- `windscribe = 2.18.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
