What is CVE-2026-48097?
CVE-2026-48097 is a command execution vulnerability in NexTor IP Changer versions before 2.0.0, caused by unsafe use of 'shell=True' combined with executable resolution via the `PATH` environment variable. This allows attackers to execute arbitrary commands. Users should immediately upgrade to version 2.0.0 or later.
Azərbaycanca: CVE-2026-48097 NexTor IP Changer alətinin 2.0.0-dən əvvəlki versiyalarında 'shell=True' parametrinin təhlükəsiz istifadə edilməməsi səbəbindən komanda icrası zəifliyi aşkar edilib. Bu, təcavüzkara `PATH` mühit dəyişəni vasitəsilə ixtiyari əmrlər icra etməyə imkan verir. İstifadəçilər dərhal 2.0.0 və ya daha yeni versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which versions of NexTor IP Changer are affected by CVE-2026-48097?
The vulnerability affects all versions of NexTor IP Changer prior to 2.0.0.
How can an attacker exploit this vulnerability to execute arbitrary commands?
An attacker can execute arbitrary commands by manipulating the `PATH` environment variable due to the unsafe use of 'shell=True'.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.