CVE-2025-10680

The OpenVPN 2.7_alpha1 through 2.7_beta1 releases are susceptible to script injection attacks when connecting to untrusted VPN services.

The pushed --dns and --dhcp-option arguments are not properly sanitised when passing them to the --dns-updown script hook, allowing them to inject additional commands being performed on the client.

This issue affects only POSIX platforms, such as BSD, Linux, MacOS and similar platforms.

Release announcement: https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00149.html

CVE Record: CVE-2025-10680

On this page
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9