CVE-2025-0781
published 2025-01-28CVE-2025-0781: An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system…
PriorityP357critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.34%
26.8th percentile
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | flightgear | < flightgear 1:2020.3.16+dfsg-1+deb12u1 (bookworm) | flightgear 1:2020.3.16+dfsg-1+deb12u1 (bookworm) |
| debian | simgear | < flightgear 1:2020.3.16+dfsg-1+deb12u1 (bookworm) | flightgear 1:2020.3.16+dfsg-1+deb12u1 (bookworm) |
| flightgear | flightgear | >= 0 < 1:2020.3.6+dfsg-1+deb11u1 | 1:2020.3.6+dfsg-1+deb11u1 |
| flightgear | flightgear | >= 0 < 1:2020.3.16+dfsg-1+deb12u1 | 1:2020.3.16+dfsg-1+deb12u1 |
| flightgear | flightgear | >= 0 < 1:2020.3.19+dfsg-1 | 1:2020.3.19+dfsg-1 |
| flightgear | flightgear | >= 0 < 1:2020.3.19+dfsg-1 | 1:2020.3.19+dfsg-1 |
| flightgear | simgear | <= 2020.3.19 | — |
| gitlab | simgear | — | — |
| simgear | simgear | >= 0 < 1:2020.3.6+dfsg-1+deb11u1 | 1:2020.3.6+dfsg-1+deb11u1 |
| simgear | simgear | >= 0 < 1:2020.3.16+dfsg-1+deb12u1 | 1:2020.3.16+dfsg-1+deb12u1 |
| simgear | simgear | >= 0 < 1:2020.3.19+dfsg-1 | 1:2020.3.19+dfsg-1 |
| simgear | simgear | >= 0 < 1:2020.3.19+dfsg-1 | 1:2020.3.19+dfsg-1 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
osv9.9CRITICAL
vendor_debian8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-0781: An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-
osv·2025-01-28·CVSS 9.9
CVE-2025-0781 [CRITICAL] CVE-2025-0781: An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
GHSA
GHSA-555q-7wq3-w6ch: An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-
ghsa_unreviewed·2025-01-28
CVE-2025-0781 [HIGH] CWE-863 GHSA-555q-7wq3-w6ch: An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Ubuntu
SimGear vulnerability
vendor_ubuntu·2026-01-15
CVE-2025-0781 SimGear vulnerability
Title: SimGear vulnerability
Summary: SimGear could be made to run programs as an administrator if it opened a
specially crafted file.
It was discovered that SimGear could be made to bypass the sandboxing of
Nasal scripts. An attacker could possibly use this issue to execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
GitLab
Incorrect Authorization in SimGear
vendor_gitlab·2025-01-28·CVSS 9.9
CVE-2025-0781 [CRITICAL] CWE-863 Incorrect Authorization in SimGear
Incorrect Authorization in SimGear
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Affected products: SimGear
Affected versions: 0 (affected)
Solution: Upgrade to FlightGear version 2020.3.20 or 2024.1.1.
Credit: Florent Rougon
Debian
CVE-2025-0781: flightgear - An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to ...
vendor_debian·2025·CVSS 8.6
CVE-2025-0781 [HIGH] CVE-2025-0781: flightgear - An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to ...
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Scope: local
bookworm: resolved (fixed in 1:2020.3.16+dfsg-1+deb12u1)
bullseye: resolved (fixed in 1:2020.3.6+dfsg-1+deb11u1)
forky: resolved (fixed in 1:2020.3.19+dfsg-1)
sid: resolved (fixed in 1:2020.3.19+dfsg-1)
trixie: resolved (fixed in 1:2020.3.19+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.com/flightgear/flightgear/-/commit/ad37afce28083fad7f79467b3ffdead753584358https://gitlab.com/flightgear/flightgear/-/issues/3025https://gitlab.com/flightgear/simgear/-/commit/5bb023647114267141a7610e8f1ca7d6f4f5a5a8https://lists.debian.org/debian-lts-announce/2025/01/msg00028.htmlhttps://lists.debian.org/debian-lts-announce/2025/01/msg00029.html
2025-01-28
Published