CVE-2020-5253: Nethack
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack 3.6.0.
Affected products
- Nethack Nethack: before 3.6.0 (fixed in 3.6.0)
Published 2020-03-10. Last modified 2026-06-17.