Command Injection Vulnerability in NexTor IP Changer by 0x5t4l1n
CVE-2026-48098
7.3HIGH
What is CVE-2026-48098?
NexTor IP Changer, a command-line tool designed to rotate IP addresses using the Tor network, contains a command injection vulnerability in versions prior to 2.0.0. This issue arises from the handling of privileged system commands executed with 'sudo' and 'shell=True' within the application logic. When passwordless sudo (NOPASSWD) is enabled, attackers can trigger privileged commands to execute silently, bypassing user confirmation entirely. This creates a significant security risk for systems utilizing the application. Version 2.0.0 addresses this vulnerability, ensuring safer execution of commands.
Affected Version(s)
NexTOR_IP_CHANGER < 2.0.0
