---
id: CVE-2025-9976
title: >-
  An OS Command Injection vulnerability affecting Station Launcher App in
  3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release
  3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the
  user's machine.
summary: >-
  An OS Command Injection vulnerability affecting Station Launcher App in
  3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release
  3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the
  user's machine.
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
published: '2025-10-13'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9976'
references:
  - url: >-
      https://www.3ds.com/trust-center/security/security-advisories/cve-2025-9976
    label: 3DS.Information-Security@3ds.com
tags:
  - nvd
epss: 0.00902
epssPercentile: 0.58066
ingestedAt: '2026-09-26T00:22:39.960Z'
---

## Overview

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
