VYPR
Medium severity6.8NVD Advisory· Published Jul 2, 2025· Updated Jun 17, 2026

CVE-2024-35164

CVE-2024-35164

Description

The terminal emulator of Apache Guacamole 1.5.5 and older does not properly validate console codes received from servers via text-based protocols like SSH. If a malicious user has access to a text-based connection, a specially-crafted sequence of console codes could allow arbitrary code to be executed with the privileges of the running guacd process.

Users are recommended to upgrade to version 1.6.0, which fixes this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.