PT-2025-33886 · Unknown · Neurobin Shc

S0L42

·

Published

2025-08-19

·

Updated

2025-09-12

·

CVE-2025-9176

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: neurobin shc versions through 4.0.3
Description: A security flaw has been discovered in neurobin shc up to version 4.0.3. The make function within the src/shc.c file of the Environment Variable Handler component is affected. Manipulation of this function results in operating system command injection. The attack is only possible with local access. The exploit has been released publicly and may be exploited.
Recommendations: For versions through 4.0.3, consider disabling or restricting the use of the make function within the Environment Variable Handler component as a temporary workaround until a patch is available.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9176

Affected Products

Neurobin Shc