CVE-2025-66005: Https://github.com/shadowblip Inputplumber

High severity, CVSS 8.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session.

Affected products

Published 2026-01-14. Last modified 2026-06-17.