CVE-2025-8078 and CVE-2024-6345: Remote Code Execution Vulnerabilities
Severity: High (Score: 71.9)
Sources: Api.Msrc.Microsoft, Twitter, Cve, Dbugs.Ptsecurity, Reddit
Summary
CVE-2025-8078, published on October 21, 2025, details a remote code execution vulnerability via CLI command injection. Additionally, CVE-2024-6345, published on July 15, 2024, affects pypa/setuptools and had its first public proof of concept released on June 27, 2025. Both vulnerabilities pose risks to users of the affected software.
Key Entities
- Remote Code Execution (attack_type)
- CVE-2024-6345 (cve)
- CVE-2025-8078 (cve)
- T1059 - Command and Scripting Interpreter (mitre_attack)