VYPR

Desktop App

by Windscribe

Source repositories

CVEs (2)

  • CVE-2026-28373CriApr 3, 2026
    risk 0.62cvss 9.6epss 0.00

    The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export can write arbitrary content to any path on the victim's filesystem.

  • CVE-2025-65199Dec 10, 2025
    risk 0.00cvss epss 0.00

    A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.