« Volver al listado

CVE-2025-58766

Estado: AplazadaCrítica (9)—

Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

UI:R indica explotación en cliente (T1203). El texto describe ejecución de código arbitrario en preview window y escape de Docker (T1059, T1068). Confianza alta por CWE-94 (código arbitrario) y descripción explícita.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-58766",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-58766",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-09-17T17:50:37.918784Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "dyad-sh",
          "product": "dyad",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.20.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-09-17T18:15:52.687",
  "references": [
    {
      "url": "https://github.com/dyad-sh/dyad/commit/1c0255ab126d3b38ae9e78b17cdab9a07e5f0185",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/dyad-sh/dyad/commit/ebcf89ee6cead83a33add5ef1e19c8d4f9b4ce9b",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/dyad-sh/dyad/security/advisories/GHSA-7fxm-c5xx-7vpq",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections.  An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system. This has been fixed in Dyad v0.20.0 and later."
    },
    {
      "lang": "es",
      "value": "Dyad es un constructor de aplicaciones de IA local. Se ha descubierto una vulnerabilidad crítica de seguridad de seguridad que afectaba a Dyad v0.19.0 y versiones anteriores que permite a los atacantes ejecutar código arbitrario en los sistemas de los usuarios. La vulnerabilidad afecta la funcionalidad de la ventana de vista previa de la aplicación y puede eludir las protecciones del contenedor Docker. Un atacante puede crear contenido web que se ejecuta automáticamente cuando la vista previa carga. El contenido malicioso puede romper los límites de seguridad de la aplicación y obtener control del sistema. Esto ha sido corregido en Dyad v0.20.0 y versiones posteriores."
    }
  ],
  "lastModified": "2026-06-17T09:44:54.103",
  "sourceIdentifier": "security-advisories@github.com"
}