CVE-2025-65199: Windscribe
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.
Affected products
- Windscribe Windscribe: from 2.10.1, up to and including 2.17.10; version 2.18.1 only; version 2.18.3 only; version 2.18.5 only
Published 2025-12-10. Last modified 2026-09-28.