PT-2025-30163 · Thor+1 · Thor+1

Odaysec

·

Published

2025-07-20

·

Updated

2026-03-13

·

CVE-2025-54314

CVSS v3.1

2.8

Low

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Thor versions prior to 1.4.0
Description Thor versions prior to 1.4.0 can construct an unsafe shell command from library input.
Recommendations Update Thor to version 1.4.0 or later.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

AZL-65613
AZL-65631
CVE-2025-54314
GHSA-MQCP-P2HV-VW6X
OPENSUSE-SU-2025:15382-1
OPENSUSE-SU-2026:10366-1

Affected Products

Debian
Thor