CVE-2020-15692
Estado: ModificadaCrítica (9.8)—
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.21%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-88
Referencias
- http://www.openwall.com/lists/oss-security/2021/02/04/1
- https://consensys.net/diligence/vulnerabilities/nim-browsers-argument-injection/
- https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/browsers.nim#L48
- https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html
- http://www.openwall.com/lists/oss-security/2021/02/04/1
- https://consensys.net/diligence/vulnerabilities/nim-browsers-argument-injection/
- https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/browsers.nim#L48
- https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-15692",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-08-14T19:15:12.317",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2021/02/04/1",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://consensys.net/diligence/vulnerabilities/nim-browsers-argument-injection/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/browsers.nim#L48",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2021/02/04/1",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://consensys.net/diligence/vulnerabilities/nim-browsers-argument-injection/",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/browsers.nim#L48",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary registered system commands."
},
{
"lang": "es",
"value": "En Nim versión 1.2.4, los navegadores de la biblioteca estándar manejan inapropiadamente el argumento de la URL para la función browsers.openDefaultBrowser. Este argumento puede ser una ruta de archivo local que será abierto en el explorador predeterminado. Un atacante puede pasar un argumento al comando abierto subyacente para ejecutar comandos arbitrarios del sistema registrado."
}
],
"lastModified": "2026-06-17T02:57:03.703",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nim-lang:nim:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DBCD9F0-7A6D-4479-948B-7B2F7B80FBF1",
"versionEndIncluding": "1.2.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}