CVE-2025-65807

An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.
References
Link Resource
http://sd.com Not Applicable
https://gist.github.com/faabbi/827f10e144fdd342e13a3dd838902e83 Exploit Third Party Advisory
https://github.com/chmln/sd Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:chmln:sd:*:*:*:*:*:*:*:*

History

17 Dec 2025, 18:20

Type Values Removed Values Added
References () http://sd.com - () http://sd.com - Not Applicable
References () https://gist.github.com/faabbi/827f10e144fdd342e13a3dd838902e83 - () https://gist.github.com/faabbi/827f10e144fdd342e13a3dd838902e83 - Exploit, Third Party Advisory
References () https://github.com/chmln/sd - () https://github.com/chmln/sd - Product
CPE cpe:2.3:a:chmln:sd:*:*:*:*:*:*:*:*
First Time Chmln sd
Chmln

11 Dec 2025, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 8.4

10 Dec 2025, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 9.8

10 Dec 2025, 17:15

Type Values Removed Values Added
CWE CWE-266
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

10 Dec 2025, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-10 16:16

Updated : 2025-12-17 18:20


NVD link : CVE-2025-65807

Mitre link : CVE-2025-65807

CVE.ORG link : CVE-2025-65807


JSON object : View

Products Affected

chmln

  • sd
CWE
CWE-266

Incorrect Privilege Assignment