CVE-2025-49809: Mtr
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.
Affected products
- Mtr Mtr: up to and including 0.95
Published 2025-07-04. Last modified 2026-06-17.