CVE-2026-48098: 0x5t4l1n Nextor IP Changer
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo (`NOPASSWD`) is enabled, privileged commands may execute silently without explicit user confirmation. Version 2.0.0 fixes the issue.
Affected products
- 0x5t4l1n Nextor IP Changer: before 2.0.0 (fixed in 2.0.0)
Published 2026-08-07. Last modified 2026-09-10.