CVE-2025-8078 and CVE-2024-6345: Remote Code Execution Vulnerabilities

CVE-2025-8078 and CVE-2024-6345: Remote Code Execution Vulnerabilities

First seen 18 Feb 2026, 23:20 UTC Api.Msrc.MicrosoftXCveDbugs.PtsecurityVulmon+2 71.9

Article Content

Browse articles
ThreatCluster

CVE-2025-8078, published on October 21, 2025, details a remote code execution vulnerability via CLI command injection. Additionally, CVE-2024-6345, published on July 15, 2024, affects pypa/setuptools and had its first public proof of concept released on June 27, 2025. Both vulnerabilities pose risks to users of the affected software.

Timeline

2024-07-15
CVE-2024-6345 published
2025-06-27
First public PoC for CVE-2024-6345 released
2025-10-21
CVE-2025-8078 published
2026-02-18
Two articles published on CVE-2025-8078 and CVE-2024-6345