TkEasyGUI OS Command Injection Vulnerability
Vulnerability
An OS command injection vulnerability has been identified in TkEasyGUI versions prior to 1.0.22. This issue allows a remote, unauthenticated attacker to execute arbitrary OS commands if the application is configured to create messages from external sources.
Impact
Exploitation of this vulnerability could lead to the execution of arbitrary OS commands on the affected system.
Remediation
Users are advised to update TkEasyGUI to version 1.0.22 or later.
Added: Sep 5, 2025, 6:19 AM
Updated: Sep 5, 2025, 6:19 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
7.4remediation
7.7relevance
0.5threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
