Blame

a999e6 David Sommerseth 2025-10-23 12:38:14 1
# CVE-2025-10680
65b531 David Sommerseth 2025-10-24 10:10:45 2
3
The OpenVPN 2.7_alpha1 through 2.7_beta1 releases are susceptible to script injection attacks when connecting to untrusted VPN services.
4
b353fb flichtenheld 2026-07-08 14:24:14 5
The pushed `--dns` and `--dhcp-option` arguments are not properly sanitised when passing them to the `--dns-updown` script hook, allowing them to inject additional commands being performed on the client.
65b531 David Sommerseth 2025-10-24 10:10:45 6
b353fb flichtenheld 2026-07-08 14:24:14 7
This issue affects only POSIX platforms, such as BSD, Linux, MacOS and similar platforms.
afdf01 David Sommerseth 2025-10-24 10:11:36 8
65b531 David Sommerseth 2025-10-24 10:10:45 9
Release announcement: [https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00149.html](https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00149.html)
10
11
CVE Record: [CVE-2025-10680](https://www.cve.org/CVERecord?id=CVE-2025-10680)