#VU103355 OS Command Injection in WPE WebKit and WebKitGTK+ - CVE-2025-24150
Published: January 27, 2025 / Updated: February 10, 2025
WPE WebKit
WebKitGTK+
WebKitGTK
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in WebKit Web Inspector. A remote attacker can trick the victim into copying a specially crafted URL from the WebKit Web Inspector and execute arbitrary OS commands on the system.