PT-2025-22454 · Poedit · Poedit

Published

2025-05-22

·

Updated

2025-05-22

·

CVE-2025-4280

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Poedit versions prior to 3.6.3
Description The MacOS version of Poedit bundles a Python interpreter that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle. An attacker with local user access can invoke this interpreter with arbitrary commands or scripts, leveraging the application's previously granted TCC permissions to access user's files in privacy-protected folders without triggering user prompts. Accessing other resources beyond previously granted TCC permissions will prompt the user for approval in the name of Poedit, potentially disguising attacker's malicious intent.
Recommendations For versions prior to 3.6.3, update to version 3.6.3 to resolve the issue. As a temporary workaround, consider restricting access to the Python interpreter bundled with Poedit to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2025-4280
GHSA-8FCW-V6GR-HP34

Affected Products

Poedit