cbcvebase.

Gnu Sed vulnerabilities

4 known vulnerabilities affecting gnu/sed.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-9155P2HIGHCVSS 8.8v4.2.22026-06-25
CVE-2026-9155 [HIGH] CWE-78 CVE-2026-9155: OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation.
nvd
CVE-2026-9153P3MEDIUMCVSS 6.5v4.2.22026-06-25
CVE-2026-9153 [MEDIUM] CWE-22 CVE-2026-9153: Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.
nvd
CVE-2026-9154P3MEDIUMCVSS 6.5v4.2.22026-06-25
CVE-2026-9154 [MEDIUM] CWE-22 CVE-2026-9154: Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression parameter.
nvd
CVE-2026-5958P4LOWCVSS 2.1≥ 4.1e, < 4.102026-04-20
CVE-2026-5958 [LOW] CWE-367 CVE-2026-5958: When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file( When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separate, non-atomic filesystem operations on the same path: 1. resolves symlink to its target and stores the resolved path for determining when output is written, 2. opens the original symlink path (not the resolved one) to read the file. B
nvd
Gnu Sed vulnerabilities | cvebase