PT-2025-33034 · Olivetin · Olivetin

Published

2025-08-13

·

Updated

2026-05-09

·

CVE-2025-50946

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Olivetin version 2025.4.22
Description OS Command Injection exists in Custom Themes through the ParseRequestURI() function located in service/internal/executor/arguments.go.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-50946
GHSA-P3QF-84RG-JXFC
GO-2025-3886
OPENSUSE-SU-2025:15469-1

Affected Products

Olivetin