CVE-2025-55294: Bencevans Screenshot-Desktop

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlled input is passed into the format option of the screenshot function, it is interpolated into a shell command without sanitization. This results in arbitrary command execution with the privileges of the calling process. This vulnerability is fixed in 1.15.2.

Affected products

  • Bencevans Screenshot-Desktop: before 1.15.2 (fixed in 1.15.2)

Published 2025-08-19. Last modified 2026-06-17.