CVE-2025-55322: Microsoft Omniparser
High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.
Affected products
- Microsoft Omniparser: before 2.0.1 (fixed in 2.0.1)
Published 2025-09-24. Last modified 2026-06-17.