VYPR

Mako Server

by Mako Server

CVEs (1)

  • CVE-2025-34095CriJul 10, 2025
    risk 0.64cvss epss 0.04

    An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp endpoint. An unauthenticated attacker can send a crafted PUT request containing arbitrary Lua os.execute() code, which…