CVE 8.8 HIGH

Eidos: One-click Remote Code Execution through Custom URL Handling_CVE-2025-54374

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted eidos: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the appโ€™s custom URL handler (eidos:), causing the Eidos application to launch and process the URL, leading to remote code execution on the victimโ€™s machine. This issue does not have a fix as of October 3, 2025

Basic Information

ID CVE-2025-54374
Source GitHub_M
Published Oct 3, 2025 at 20:00

Affected Product

Vendor mayneyao
Product eidos
Version <= 0.21.0
Affected Versions mayneyao eidos <= 0.21.0

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.