CVE-2025-55294: Bencevans Screenshot-Desktop
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with the privileges of the calling process. This vulnerability is fixed in 1.15.2.
Affected products
- Bencevans Screenshot-Desktop: before 1.15.2 (fixed in 1.15.2)
Published 2025-08-19. Last modified 2026-06-17.