CVE-2013-7416: Canto Curses

High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.

canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.

Affected products

  • Canto Canto Curses: up to and including 0.9.0; version 0.8.4 only; version 0.9.0 only

Published 2014-12-03. Last modified 2026-06-17.