High severity8.6NVD Advisory· Published Jan 28, 2025· Updated Jun 17, 2026
CVE-2025-0781
CVE-2025-0781
Description
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:flightgear:simgear:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:flightgear:simgear:*:*:*:*:*:*:*:*range: <=2020.3.19
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
5- gitlab.com/flightgear/flightgear/-/commit/ad37afce28083fad7f79467b3ffdead753584358nvdPatch
- gitlab.com/flightgear/simgear/-/commit/5bb023647114267141a7610e8f1ca7d6f4f5a5a8nvdPatch
- lists.debian.org/debian-lts-announce/2025/01/msg00028.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/01/msg00029.htmlnvdMailing ListThird Party Advisory
- gitlab.com/flightgear/flightgear/-/issues/3025nvdBroken Link
News mentions
0No linked articles in our index yet.