Command Execution Vulnerability in NexTor IP Changer by 0x5t4l1n
CVE-2026-48097

7.8HIGH

Key Information:

Vendor

0x5t4l1n

Vendor
CVE Published:
7 August 2026

What is CVE-2026-48097?

The NexTor IP Changer, a tool designed to rotate user IP addresses via the Tor network, is vulnerable to command execution owing to improper handling of command execution with shell=True. This flaw permits an attacker to manipulate the execution environment to introduce malicious executables into the PATH, thereby allowing the execution of arbitrary code. Users are advised to update to version 2.0.0 which addresses this security concern effectively.

Affected Version(s)

NexTOR_IP_CHANGER < 2.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.