#VU76489 OS Command Injection in texlive - CVE-2023-32700
Published: May 25, 2023 / Updated: November 25, 2025
texlive
TeX Users Group
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing a TeX file, obtain from an untrusted source. A remote attacker can pass specially crafted file to the application and execute arbitrary OS commands on the target system.