CVE-2012-4245: Gimp

Medium severity, CVSS 6.8. EPSS: 4.7% chance of exploitation in the next 30 days.

The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

Affected products

  • Gimp Gimp: from 2.6.0, up to and including 2.6.13

Published 2012-08-31. Last modified 2026-06-16.