VYPR

Mako Server

by Real Time Logic

CVEs (1)

  • CVE-2025-34095CriJul 10, 2025
    risk 0.69cvss epss 0.67

    An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial interface provided by the examples/save.lsp endpoint. An unauthenticated attacker can send a crafted PUT request containing arbitrary Lua os.execute() code, which…