FlawAtlas
Search the atlas
CVE-2025-5030 Low

Ackites KillWxapkg vulnerable to OS Command Injection in github.com/Ackites/KillWxapkg

Ackites KillWxapkg vulnerable to OS Command Injection in github.com/Ackites/KillWxapkg

Exploit probability 2.3%
Published July 28, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

4 explicit affected versions

Go github.com/Ackites/KillWxapkg
Go github.com/Ackites/KillWxapkg

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3773

Ackites KillWxapkg vulnerable to OS Command Injection in github.com/Ackites/KillWxapkg

View original source
Open Source Vulnerabilities GHSA-w6p4-84vc-qc2w

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file internal/unpack/unpack.go of the component wxapkg File Parser. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

View original source
Open Source Vulnerabilities CVE-2025-5030

A vulnerability was found in Ackites KillWxapkg up to 2.4.1. It has been declared as critical. This vulnerability affects the function processFile of the file internal/unpack/unpack.go of the component wxapkg File Parser. The manipulation leads to os command injection. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

View original source

05 / REFERENCES

Further evidence