Commit 65b531

2025-10-24 10:10:45 David Sommerseth: Initial CVE description
Security Announcements/CVE-2025-10680.md ..
@@ 1,1 1,9 @@
# CVE-2025-10680
+
+ The OpenVPN 2.7_alpha1 through 2.7_beta1 releases are susceptible to script injection attacks when connecting to untrusted VPN services.
+
+ The pushed --dns and --dhcp-option arguments are not properly sanitised when passing them to the --dns-updown script hook, allowing them to inject additional commands being performed on the client.
+
+ Release announcement: [https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00149.html](https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00149.html)
+
+ CVE Record: [CVE-2025-10680](https://www.cve.org/CVERecord?id=CVE-2025-10680)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9